漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.
Vulnerability Description
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication to perform a Man-in-the-Middle (MitM) attack, which may obtain the sensitive information of DDNS updating process, including the user's account email, MD5 hashed password, and device serial number.This issue affects ADM: from 4.1.0 through 4.3.3.ROF1, from 5.0.0 through 5.1.1.RCI1.
CVSS Information
N/A
Vulnerability Type
证书验证不恰当
Vulnerability Title
ASUSTOR ADM 安全漏洞
Vulnerability Description
ASUSTOR ADM是中国华芸科技(ASUSTOR)公司的一种所有 ASUSTOR NAS 设备的专用操作系统。 ASUSTOR ADM 4.1.0版本至4.3.3.ROF1版本和5.0.0版本至5.1.1.RCI1版本存在安全漏洞,该漏洞源于DDNS更新功能未正确验证TLS/SSL证书主机名,可能导致中间人攻击并获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A