CVE-2018-15697: Infoleak
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ashhistory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15697?
CVE-2018-15697 is a vulnerability in ASUSTOR Data Master 3.1.5 and below that allows authenticated remote non-administrative users to read any file on a share by providing the full path.
How can authenticated remote non-administrative users exploit CVE-2018-15697?
Authenticated remote non-administrative users can exploit CVE-2018-15697 by providing the full path of a file on a share to read it.
What is the severity of CVE-2018-15697?
CVE-2018-15697 has a severity value of 6.5 (medium).
How can I fix CVE-2018-15697 in ASUSTOR Data Master?
To fix CVE-2018-15697 in ASUSTOR Data Master, it is recommended to update to a version above 3.1.5.
Where can I find more information about CVE-2018-15697?
You can find more information about CVE-2018-15697 at the following link: [CVE-2018-15697](https://www.tenable.com/security/research/tra-2018-22)