Vulnerability Details CVE-2018-15697
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2018-15697
-
cpe:2.3:o:asustor:data_master:2.1
-
cpe:2.3:o:asustor:data_master:2.5
-
cpe:2.3:o:asustor:data_master:2.6
-
cpe:2.3:o:asustor:data_master:3.0
-
cpe:2.3:o:asustor:data_master:3.0.2.ra22
-
cpe:2.3:o:asustor:data_master:3.0.5.rdu1
-
cpe:2.3:o:asustor:data_master:3.1.0.rfq3
-
cpe:2.3:o:asustor:data_master:3.1.1
-
cpe:2.3:o:asustor:data_master:3.1.1.rgg1
-
cpe:2.3:o:asustor:data_master:3.1.2.rhg1
-
cpe:2.3:o:asustor:data_master:3.1.3.rhu2
-
cpe:2.3:o:asustor:data_master:3.1.4.rdi1
-
cpe:2.3:o:asustor:data_master:3.1.4.rid1
-
cpe:2.3:o:asustor:data_master:3.1.5