Vulnerability Details CVE-2018-18471
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.155
EPSS Ranking 94.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2018-18471
-
cpe:2.3:h:medion:lifecloud:-
-
cpe:2.3:h:netgear:stora:-
-
cpe:2.3:h:seagate:goflex_home:-
-
cpe:2.3:o:axentra:hipserv:-