Asustor

Data Master

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 22.08.2023 19:16:41
  • Zuletzt bearbeitet 21.11.2024 08:35:14

An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below a...

  • EPSS 0.05%
  • Veröffentlicht 22.08.2023 19:16:39
  • Zuletzt bearbeitet 21.11.2024 08:17:52

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as A...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:17:52

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM ...

  • EPSS 0.31%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:17:52

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM ...

  • EPSS 0.56%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:33

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Af...

Exploit
  • EPSS 11.98%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:59

Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.

Exploit
  • EPSS 11.98%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.

Exploit
  • EPSS 11.98%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.