vendor:
Grab’n’Go Network Storage
by:
Alcyon
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Grab’n’Go Network Storage
Affected Version From: 3.0.12
Affected Version To: 2.4.13
Patch Exists: NO
Related CWE: N/A
CPE: h:conceptronic:grab_n_go_network_storage
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Security Advisory AA-003: Directory Traversal Vulnerability in Conceptronic Grab’n’Go Network Storage
An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacer could steal sensitive data stored on the device; leverage the device to drop and/or host malware; abuse the device to send spam through the victim’s Internet connection; use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.
Mitigation:
Limit access to the devices's web management UI by utilizing proper packet filtering and/or NAT on your router in order to limit network access to your NAS.