CVE-2018-12301: Infoleak
Published May 13, 2019
·Updated
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
Affected Software
1 affected component
Seagate NAS OS=4.3.15.1
Event History
May 13, 2019
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12301?
CVE-2018-12301 has been classified with a high severity due to its potential to allow unauthorized access to sensitive interfaces.
2
How do I fix CVE-2018-12301?
To fix CVE-2018-12301, ensure that your Seagate NAS OS is updated to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2018-12301?
The impact of CVE-2018-12301 is that it allows attackers to access the loopback interface by exploiting unvalidated URLs.
4
Who is affected by CVE-2018-12301?
CVE-2018-12301 affects users running Seagate NAS OS version 4.3.15.1.
5
Is there a workaround for CVE-2018-12301?
Currently, there are no documented workarounds for CVE-2018-12301 other than upgrading to a patched version.