← Back

CVE-2018-0712

nvd nist
Published: Jun 21, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.

Affected (3)

Products: Qnap: Qts
1 product
Qts
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.2.6
Version 4.3.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.3.4

References (4)

Source: security@qnapsecurity.com.tw
Third Party AdvisoryVDB Entry
Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.