Seagate NAS OS version 4.3.15.1 has insufficient access control which allows attackers to obtain information about the NAS without authentication via empty POST requests in /api/external/7.0/system.System.get_infos.
id: CVE-2018-12296
info:
name: Seagate NAS OS 4.3.15.1 - Server Information Disclosure
author:
...