PT-2013-3912 · NetGear · Readynas Raidiator

Published

2013-12-12

·

Updated

2019-07-18

·

CVE-2013-2751

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ReadyNAS RAIDiator versions prior to 4.1.12 ReadyNAS RAIDiator versions 4.2.x prior to 4.2.24
Description The issue is related to an eval injection vulnerability in the FrontView web interface, specifically in the frontview/lib/np handler.pl file. This vulnerability allows remote attackers to execute arbitrary Perl code via a crafted request, which is related to the "forgot password workflow."
Recommendations For ReadyNAS RAIDiator versions prior to 4.1.12, update to version 4.1.12 or later. For ReadyNAS RAIDiator versions 4.2.x prior to 4.2.24, update to version 4.2.24 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2751

Affected Products

Readynas Raidiator