← Back

CVE-2018-0730

nvd nist
Published: Dec 4, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Affected (25)

Products: Qnap: Qts
1 product
Qts
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.2.6
Version 4.3.3.0868
Version 4.3.3.0998
Version 4.3.4.0899
Version 4.3.4.1029
Version 4.3.6.0895
Version 4.3.6.0907
Version 4.3.6.0923
Version 4.3.6.0944
Version 4.3.6.0959
Version 4.3.6.0979
Version 4.3.6.0993
Version 4.3.6.1013
Version 4.3.6.1033
Version 4.4.1.0948 beta
Version 4.4.1.0949 beta
Version 4.4.1.0978 beta_2
Version 4.4.1.0998 beta_3
Version 4.4.1.0999 beta_3
Version 4.4.1.1031 beta_4
Version 4.4.1.1033 beta_4
Version 4.4.1.1064
Version 4.4.1.1081
Version 4.4.1.1086
Version 4.4.1.1101

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.