Asustor

Data Master

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 12.12.2025 02:30:35
  • Zuletzt bearbeitet 28.01.2026 14:53:53

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle...

  • EPSS 0.16%
  • Veröffentlicht 22.08.2023 19:16:41
  • Zuletzt bearbeitet 21.11.2024 08:35:14

An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below a...

  • EPSS 0.15%
  • Veröffentlicht 22.08.2023 19:16:39
  • Zuletzt bearbeitet 21.11.2024 08:17:52

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as A...

  • EPSS 0.53%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:17:52

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM ...

  • EPSS 0.55%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:17:52

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM ...

  • EPSS 1.34%
  • Veröffentlicht 17.08.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:33

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Af...

Exploit
  • EPSS 3.44%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.

Exploit
  • EPSS 1.18%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:59

Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.

Exploit
  • EPSS 3.44%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:58

OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.