Vulnerability Details CVE-2018-15696
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.3%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2018-15696
-
cpe:2.3:o:asustor:data_master:2.1
-
cpe:2.3:o:asustor:data_master:2.5
-
cpe:2.3:o:asustor:data_master:2.6
-
cpe:2.3:o:asustor:data_master:3.0
-
cpe:2.3:o:asustor:data_master:3.0.2.ra22
-
cpe:2.3:o:asustor:data_master:3.0.5.rdu1
-
cpe:2.3:o:asustor:data_master:3.1.0.rfq3
-
cpe:2.3:o:asustor:data_master:3.1.1
-
cpe:2.3:o:asustor:data_master:3.1.1.rgg1
-
cpe:2.3:o:asustor:data_master:3.1.2.rhg1
-
cpe:2.3:o:asustor:data_master:3.1.3.rhu2
-
cpe:2.3:o:asustor:data_master:3.1.4.rdi1
-
cpe:2.3:o:asustor:data_master:3.1.4.rid1
-
cpe:2.3:o:asustor:data_master:3.1.5