Lucene search

K

Nas Security Vulnerabilities

cve
cve

CVE-2002-1955

Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack.

7.2AI Score

0.002EPSS

2022-10-03 04:23 PM
24
cve
cve

CVE-2013-0142

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

7AI Score

0.003EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2013-0143

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

7.6AI Score

0.055EPSS

2022-10-03 04:15 PM
26
cve
cve

CVE-2022-24551

A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633.

8.8CVSS

8.5AI Score

0.001EPSS

2022-02-06 09:15 PM
41
2
cve
cve

CVE-2022-24552

A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root ...

9.8CVSS

9.3AI Score

0.005EPSS

2022-02-06 09:15 PM
46