Vulnerabilities > Actidata

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2023-51946 Cross-site Scripting vulnerability in Actidata Actinas SL 2U-8 RDX Firmware 3.2.03
Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.
network
low complexity
actidata CWE-79
6.1
2024-01-19 CVE-2023-51947 Missing Authentication for Critical Function vulnerability in Actidata Actinas SL 2U-8 RDX Firmware 3.2.03
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
network
low complexity
actidata CWE-306
critical
9.1
2024-01-19 CVE-2023-51948 Unspecified vulnerability in Actidata Actinas SL 2U-8 RDX Firmware 3.2.03
A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web application.
network
low complexity
actidata
7.5