Skip to content
COOEY

EXPOSURES › CVE-2018-14839

CVE-2018-14839

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-14839 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

LG N1A1 NAS devices suffer from a remote code execution vulnerability that allows attackers to execute arbitrary commands remotely.

LG N1A1 NAS devices are affected by CVE-2018-14839, a remote code execution vulnerability that allows attackers to execute arbitrary commands remotely. This failure is critical for DIB organizations because NAS devices often store sensitive data, and an RCE vulnerability can lead to data breaches, ransomware attacks, or complete system compromise. Organizations must ensure all NAS devices are patched and monitored for signs of exploitation.

Shame score — The vulnerability is actively exploited in the wild (KEV list) and allows remote code execution, indicating a severe security gap that could lead to data breaches or ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.