Vulnerabilities > Asustor > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-17 | CVE-2023-2910 | Command Injection vulnerability in Asustor Data Master Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. | 8.8 |
2023-08-17 | CVE-2023-3697 | Path Traversal vulnerability in Asustor Data Master Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. | 8.8 |
2023-08-17 | CVE-2023-3698 | Path Traversal vulnerability in Asustor Data Master Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. | 8.1 |
2023-05-31 | CVE-2023-2749 | Incorrect Default Permissions vulnerability in Asustor Download Center Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. | 7.5 |
2022-08-05 | CVE-2022-37398 | Out-of-bounds Write vulnerability in Asustor ADM A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. | 8.8 |
2020-03-18 | CVE-2019-11689 | OS Command Injection vulnerability in Asustor Exfat Driver 1.0.0 An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. | 8.1 |
2020-03-18 | CVE-2019-11688 | Improper Certificate Validation vulnerability in Asustor Exfat Driver 1.0.0 An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. | 7.4 |
2018-12-04 | CVE-2018-12319 | Cross-site Scripting vulnerability in Asustor Data Master 3.1.1 Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. | 7.5 |
2018-12-04 | CVE-2018-12318 | Information Exposure vulnerability in Asustor Data Master 3.1.1 Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext. | 8.8 |
2018-12-04 | CVE-2018-12317 | OS Command Injection vulnerability in Asustor Data Master 3.1.1 OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter. | 8.8 |