vendor:
MD-253
by:
Alcyon
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: MD-253
Affected Version From: 2.4.17
Affected Version To: 2.4.17
Patch Exists: NO
Related CWE: N/A
CPE: h:sitecom:md-253
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Security Advisory AA-004: Directory Traversal Vulnerability in Sitecom Home Storage Center
An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacker could steal sensitive data stored on the device, leverage the device to drop and/or host malware, abuse the device to send spam through the victim’s Internet connection, and use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.
Mitigation:
We recommend that you limit access to the devices's web management UI by utilizing proper packet filtering and/or NAT on your router in order to limit network access to your NAS.