Description
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
In plain language
AI Worth attentionCVE-2018-12296 is a weakness in Seagate NAS OS that lets someone gather information about your NAS without logging in; if your NAS is exposed to the internet, you should treat this as a real, fix-priority issue.
Unauthenticated information disclosure via Insufficient Access Control in Seagate NAS OS, affecting /api/external/7.0/system.System.get_infos, where empty POST requests can return system information without authentication; a public exploit exists.
What to do now
- Check whether you run Seagate NAS OS and confirm the version matches Seagate NAS OS 4.3.15.1.
- Determine whether the /api/external/7.0/system.System.get_infos endpoint is reachable from the internet (for example, from outside your office/home network).
- If it is internet-reachable, restrict access now so the NAS management/API is only reachable from trusted internal networks (or via a VPN).
- Look for an official Seagate update that addresses CVE-2018-12296; if no fixed version is available, contact Seagate support for a mitigation path and document their guidance.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-12296 and every CVE in our database. Create a free account — no credit card required.
Create Free Account