cbcvebase.

Seagate Nas Os vulnerabilities

10 known vulnerabilities affecting seagate/nas_os.

Total CVEs
10
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2018-12296P2HIGHCVSS 7.5ExploitedPoCv4.3.15.12019-05-13
CVE-2018-12296 [HIGH] CWE-732 CVE-2018-12296: Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4 Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
nvd
CVE-2018-12300P3MEDIUMCVSS 6.1PoCv4.3.15.12019-05-13
CVE-2018-12300 [MEDIUM] CWE-601 CVE-2018-12300: Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclo Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
nvd
CVE-2018-12295P3CRITICALCVSS 9.8v4.3.15.12019-05-13
CVE-2018-12295 [CRITICAL] CWE-89 CVE-2018-12295: SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execu SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
nvd
CVE-2018-12298P3HIGHCVSS 7.5v4.3.15.12019-05-13
CVE-2018-12298 [HIGH] CWE-22 CVE-2018-12298: Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
nvd
CVE-2018-12301P3HIGHCVSS 7.5v4.3.15.12019-05-13
CVE-2018-12301 [HIGH] CWE-200 CVE-2018-12301: Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access th Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
nvd
CVE-2018-12303P4MEDIUMCVSS 5.4v4.3.15.12019-05-13
CVE-2018-12303 [MEDIUM] CWE-79 CVE-2018-12303: Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute J Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
nvd
CVE-2018-12304P4MEDIUMCVSS 6.1v4.3.15.12019-05-13
CVE-2018-12304 [MEDIUM] CWE-79 CVE-2018-12304: Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to e Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
nvd
CVE-2018-12302P4MEDIUMCVSS 6.1v4.3.15.12019-05-13
CVE-2018-12302 [MEDIUM] CWE-79 CVE-2018-12302: Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allo Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
nvd
CVE-2018-12297P4MEDIUMCVSS 6.1v4.3.15.12019-05-13
CVE-2018-12297 [MEDIUM] CWE-79 CVE-2018-12297: Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execu Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
nvd
CVE-2018-12299P4MEDIUMCVSS 5.4v4.3.15.12019-05-13
CVE-2018-12299 [MEDIUM] CWE-79 CVE-2018-12299: Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute J Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
nvd
Seagate Nas Os vulnerabilities | cvebase