Vulnerabilities > Seagate > NAS OS > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-13 CVE-2018-12301 Information Exposure vulnerability in Seagate NAS OS 4.3.15.1
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
network
low complexity
seagate CWE-200
7.5
2019-05-13 CVE-2018-12298 Path Traversal vulnerability in Seagate NAS OS 4.3.15.1
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
network
low complexity
seagate CWE-22
7.5
2019-05-13 CVE-2018-12296 Incorrect Permission Assignment for Critical Resource vulnerability in Seagate NAS OS 4.3.15.1
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
network
low complexity
seagate CWE-732
7.5