ASUSTOR ADM
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*, +1 more
- >= 4.1.0, <= 4.3.3.RKD2
- >= 5.0.0, <= 5.1.0.RN42
A vulnerability exists in Asustor ADM versions 4.1.0 prior to 4.3.3.RKD2 and 5.0.0 prior to 5.1.0.RN42. When users configure the Notification sender to use msmtp for SMTP email delivery, the application fails to properly validate TLS/SSL certificates. This flaw allows an attacker to intercept network traffic between the SMTP client and server, executing a man-in-the-middle (MITM) attack that could capture sensitive information being transmitted via SMTP.
Exploitation of this vulnerability could lead to a man-in-the-middle (MITM) attack, allowing interception and potential misuse of sensitive information sent from the SMTP client to the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.