CVE-2018-15696: Infoleak
Published Aug 27, 2018
·Updated
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
Affected Software
1 affected component
ASUSTOR Data Master<=3.1.5
Event History
Aug 27, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for ASUSTOR Data Master 3.1.5 and below?
The vulnerability ID for ASUSTOR Data Master 3.1.5 and below is CVE-2018-15696.
2
What is the severity level of CVE-2018-15696?
The severity level of CVE-2018-15696 is medium (4.3).
3
How does CVE-2018-15696 impact ASUSTOR Data Master?
CVE-2018-15696 allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi in ASUSTOR Data Master 3.1.5 and below.
4
How can I fix CVE-2018-15696 in ASUSTOR Data Master?
To fix CVE-2018-15696 in ASUSTOR Data Master, update to a version higher than 3.1.5 as this vulnerability has been patched.
5
Where can I find more information about CVE-2018-15696?
More information about CVE-2018-15696 can be found at the following link: [https://www.tenable.com/security/research/tra-2018-22](https://www.tenable.com/security/research/tra-2018-22)