Vulnerability Details CVE-2018-15694
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.0
Products affected by CVE-2018-15694
-
cpe:2.3:o:asustor:data_master:2.1
-
cpe:2.3:o:asustor:data_master:2.5
-
cpe:2.3:o:asustor:data_master:2.6
-
cpe:2.3:o:asustor:data_master:3.0
-
cpe:2.3:o:asustor:data_master:3.0.2.ra22
-
cpe:2.3:o:asustor:data_master:3.0.5.rdu1
-
cpe:2.3:o:asustor:data_master:3.1.0.rfq3
-
cpe:2.3:o:asustor:data_master:3.1.1
-
cpe:2.3:o:asustor:data_master:3.1.1.rgg1
-
cpe:2.3:o:asustor:data_master:3.1.2.rhg1
-
cpe:2.3:o:asustor:data_master:3.1.3.rhu2
-
cpe:2.3:o:asustor:data_master:3.1.4.rdi1
-
cpe:2.3:o:asustor:data_master:3.1.4.rid1
-
cpe:2.3:o:asustor:data_master:3.1.5