← Back

CVE-2017-7638

nvd nist
Published: Mar 8, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

Affected (2)

1 product
Media Streaming Add On
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 430.1.2.0
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 421.1.0.2
Running on/withPlatform Versions
Qnap
Qts
Up to 4.2.6

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.