CVE-2018-12315: Medium severity asustor data master vulnerability
Published Dec 4, 2018
·Updated
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12315?
CVE-2018-12315 is a vulnerability in ASUSTOR ADM version 3.1.1 that allows attackers to change account passwords without entering the current password.
2
What software is affected by CVE-2018-12315?
ASUSTOR ADM version 3.1.1 is affected by CVE-2018-12315.
3
What is the severity of CVE-2018-12315?
CVE-2018-12315 has a severity rating of medium (6.5).
4
How can attackers exploit CVE-2018-12315?
Attackers can exploit CVE-2018-12315 to change account passwords without having to enter the current password.
5
Is there a fix for CVE-2018-12315?
A fix for CVE-2018-12315 is not provided in the information available.