VYPR

actiNAS-SL-2U-8

by actidata

CVEs (3)

  • CVE-2023-51947CriJan 19, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

  • CVE-2023-51948HigJan 19, 2024
    risk 0.49cvss 7.5epss 0.01

    A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web application.

  • CVE-2023-51946MedJan 19, 2024
    risk 0.40cvss 6.1epss 0.00

    Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.