CVE-2018-12296

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/05/2019
Last modified:
03/10/2019

Description

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:seagate:nas_os:4.3.15.1:*:*:*:*:*:*:*