Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
The nasSvr.php file handling NAS server functions does not require any authentication before performing operations on data. An attacker can directly send HTTP requests to this endpoint from the network without needing to possess credentials. In this way, they gain access to various types of data and can modify them arbitrarily. The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function).
An attacker can read sensitive data stored on the NAS device without authentication and modify it, leading to a breach of confidentiality and integrity of stored information.
Apply patches available from the manufacturer according to the references. As a temporary measure, it is recommended to restrict network access to the device management panel through firewall rules to prevent unauthorized entities from accessing the administrative interface.
actidata actiNAS SL 2U-8 RDX firmware version 3.2.03-SP1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NActidata Actinas Sl 2u 8 Rdx
HWActidataall versionsActidata Actinas Sl 2u 8 Rdx Firmware
OSActidata3.2.03