CVE-2018-12296: High severity seagate nas os vulnerability
Insufficient access control in /api/external/7.0/system.System.getinfos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12296?
CVE-2018-12296 has been classified with a high severity due to its potential for unauthorized information disclosure.
How do I fix CVE-2018-12296?
The recommended fix for CVE-2018-12296 is to upgrade to a patched version of Seagate NAS OS that addresses the insufficient access control.
What kind of information can be accessed through CVE-2018-12296?
CVE-2018-12296 allows attackers to obtain sensitive information about the NAS, such as configuration or status details, without authentication.
What versions of Seagate NAS OS are affected by CVE-2018-12296?
CVE-2018-12296 specifically affects Seagate NAS OS version 4.3.15.1.
Is authentication required to exploit CVE-2018-12296?
No, CVE-2018-12296 can be exploited without authentication by sending empty POST requests.