Описание
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:seagate:nas_os:4.3.15.1:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.75166
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
github
больше 3 лет назад
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
EPSS
Процентиль: 99%
0.75166
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-732