CVE-2018-15697 is a vulnerability in ASUSTOR Data Master (ADM) versions 3.1.5 and below, allowing authenticated non-administrative users to read any file on a shared directory by providing its full path. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and requires user authentication, but can lead to high confidentiality impact as sensitive files like .ash_history can be accessed. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.5CPE matchmatch criteria | cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Multiple ASUSTOR Data Master Vulnerabilities
Aug 24, 2018[R1] Multiple ASUSTOR Data Master Vulnerabilities
Aug 24, 2018Multiple ASUSTOR Data Master Vulnerabilities
Aug 24, 2018[R1] Multiple ASUSTOR Data Master Vulnerabilities
Aug 24, 2018