CVE Vulnerabilities

CVE-2018-11346

Direct Request ('Forced Browsing')

Published: May 22, 2018 | Modified: Oct 03, 2019
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the download_sys_settings action and then specify files arbitrarily throughout the system via the act parameter.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
As6202t_firmware Asustor * adm_3.1.0.rfq3 (including)

Potential Mitigations

References