When the user set the Notifications sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Data_master | Asustor | 4.1.0.RHU2 (including) | 4.3.3.ROF1 (excluding) |
| Data_master | Asustor | 5.0.0.ra82 (including) | 5.1.1.RCI1 (excluding) |