CVE-2018-12308: Infoleak
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encryptkey" URL parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12308?
CVE-2018-12308 is a vulnerability in ASUSTOR ADM version 3.1.1 that allows attackers to obtain the encryption key.
How can attackers exploit CVE-2018-12308?
Attackers can exploit CVE-2018-12308 by using the "encrypt_key" URL parameter in share.cgi to obtain the encryption key.
What is the severity of CVE-2018-12308?
CVE-2018-12308 has a severity level of medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-12308?
ASUSTOR ADM version 3.1.1 is affected by CVE-2018-12308.
Where can I find more information about CVE-2018-12308?
You can find more information about CVE-2018-12308 at the following link: [https://blog.securityevaluators.com/over-a-dozen-vulnerabilities-discovered-in-asustor-as-602t-8dd5832a82cc](https://blog.securityevaluators.com/over-a-dozen-vulnerabilities-discovered-in-asustor-as-602t-8dd5832a82cc)