CVE-2018-11342: Path Traversal
Published May 22, 2018
·Updated
A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the destfolder parameter.
Affected Software
2 affected components
ASUSTOR As6202t Firmware<=adm_3.1.0.rfq3
ASUSTOR AS6202T
Event History
May 22, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11342.
2
What is the severity of CVE-2018-11342?
The severity of CVE-2018-11342 is medium with a score of 4.3.
3
How does CVE-2018-11342 allow attackers to exploit the system?
CVE-2018-11342 allows attackers to create folders on the system by arbitrarily specifying a path to a file using the dest_folder parameter in fileExplorer.cgi.
4
Which versions of ASUSTOR AS6202T ADM are affected by CVE-2018-11342?
CVE-2018-11342 affects ASUSTOR AS6202T ADM 3.1.0.RFQ3.
5
How can I mitigate the vulnerability in ASUSTOR AS6202T ADM 3.1.0.RFQ3?
To mitigate the vulnerability in ASUSTOR AS6202T ADM 3.1.0.RFQ3, apply the latest firmware update provided by ASUSTOR.