An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
References
Link | Resource |
---|---|
https://www.asustor.com/security/security_advisory_detail?id=30 | Vendor Advisory |
https://www.asustor.com/security/security_advisory_detail?id=30 | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.asustor.com/security/security_advisory_detail?id=30 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
28 Aug 2023, 20:33
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
First Time |
Asustor data Master
Asustor |
|
References | (MISC) https://www.asustor.com/security/security_advisory_detail?id=30 - Vendor Advisory | |
CWE | CWE-552 | |
CPE | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* |
22 Aug 2023, 20:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-22 19:16
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4475
Mitre link : CVE-2023-4475
CVE.ORG link : CVE-2023-4475
JSON object : View
Products Affected
asustor
- data_master
CWE
CWE-552
Files or Directories Accessible to External Parties