ASUSTOR ADM
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*, +1 more
- >= 4.1.0, <= 4.3.3.RKD2
- >= 5.0.0, <= 5.1.0.RN42
A vulnerability exists in Asustor's ADM operating system, specifically in versions 4.1.0 prior to 4.3.3.RKD2 and 5.0.0 prior to 5.1.0.RN42. The issue arises from non-enforced TLS certificate verification when users configure the NAS to manage UPS settings. This flaw allows an attacker to intercept network traffic between the client and server, potentially leading to a man-in-the-middle (MITM) attack. Exploitation of this vulnerability could result in unauthorized access to sensitive information regarding the UPS server configuration.
Exploitation of this vulnerability could allow an attacker to intercept and manipulate network traffic, accessing sensitive UPS configuration information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.