CRITICAL🇵🇱 Wersja polska

CVE-2023-51947

CVSS 9.1v3.1pub. 2024-01-19upd. 2026-07-09

Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

🤖 AI Analysis
How it works

The nasSvr.php file handling NAS server functions does not require any authentication before performing operations on data. An attacker can directly send HTTP requests to this endpoint from the network without needing to possess credentials. In this way, they gain access to various types of data and can modify them arbitrarily. The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function).

Impact

An attacker can read sensitive data stored on the NAS device without authentication and modify it, leading to a breach of confidentiality and integrity of stored information.

Mitigation & patch

Apply patches available from the manufacturer according to the references. As a temporary measure, it is recommended to restrict network access to the device management panel through firewall rules to prevent unauthorized entities from accessing the administrative interface.

Who is affected

actidata actiNAS SL 2U-8 RDX firmware version 3.2.03-SP1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Actidata Actinas Sl 2u 8 Rdx

    HW
    Actidata
    all versions
  • Actidata Actinas Sl 2u 8 Rdx Firmware

    OS
    Actidata
    3.2.03
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-51948HIGH7.5same product

A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote at...

CVE-2023-51946MEDIUM6.1same product

Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03...