S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-12296 Scanner

CVE-2018-12296 scanner - Information Disclosure vulnerability in Seagate NAS OS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-12296
7.5
CVSS

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Seagate NAS OS is a storage operating system designed for Seagate's Network Attached Storage (NAS) devices. It enables users to store and manage their digital files from a central location, providing easy access and seamless sharing for multiple users. Seagate NAS OS is easy to use and designed for personal and business use, making it a popular choice for those looking for a simple and efficient solution for managing their data.

The CVE-2018-12296 vulnerability is a major security issue that was discovered in Seagate NAS OS version 4.3.15.1. The vulnerability is caused by insufficient access control in the /api/external/7.0/system.System.get_infos endpoint, allowing attackers to obtain sensitive information about the NAS without proper authentication via empty POST requests. This vulnerability exposes user data and passwords, essentially creating a backdoor into the device, which can be exploited for malicious purposes.

If this vulnerability is exploited, the attackers can gain unauthorized access to the Seagate NAS device, which can lead to data theft, sabotage, and sensitive information leakage. This can have severe consequences for personal users and businesses alike, as data loss or theft can have negative effects on the company's revenue, reputation, and customer trust.

In conclusion, the CVE-2018-12296 vulnerability in Seagate NAS OS is a serious security issue that can have severe consequences for individuals and businesses alike. It is crucial for users of the Seagate NAS devices to take precautions and ensure that their devices are protected against such attacks. With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets, making it an essential tool for protecting their overall cyber security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Seagate NAS devices should take the following steps:

  • Upgrade to the latest version of Seagate NAS OS, which fixes the vulnerability.
  • Restrict access to the device to only those who need it, such as authorized users.
  • Monitor the device for any malicious activity, such as unauthorized access or changes to configuration settings.
  • Enable two-factor authentication to add an additional layer of security.
  • Regularly back up your data to an external location.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-12296 scanner - Information Disclosure vulnerability in Seagate NAS OS | S4E