← Vulnerability feed

Vulnerability record · CVE-2018-12296 · published 13 May 2019

CVE-2018-12296: Seagate nas os incorrect permission assignment vulnerability

Seagate · Nas Os

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

7.5 CVSS 3.0 High EPSS 11% · top 4.2% CWE-732 · Incorrect permission assignment
7.5CVSS 3.0 base score, v2 5.0
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12295Seagate nas os sql injection vulnerabilitySQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL param…EPSS 1.1%7.5CVE-2018-12298Seagate nas os path traversal vulnerabilityDirectory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.EPSS 1.7%7.5CVE-2018-12301Seagate nas os information exposure vulnerabilityUnvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…EPSS 1.4%6.1CVE-2018-12297Seagate nas os cross-site scripting vulnerabilityCross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.EPSS 0.69%6.1CVE-2018-12300Seagate nas os open redirect vulnerabilityArbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…EPSS 3.1%6.1CVE-2018-12302Seagate nas os cross-site scripting vulnerabilityMissing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-si…EPSS 0.80%6.1CVE-2018-12304Seagate nas os cross-site scripting vulnerabilityCross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metada…EPSS 0.83%5.4CVE-2018-12299Seagate nas os cross-site scripting vulnerabilityCross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2018-12296), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.