Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-7261


The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.


Published

2016-02-27T05:59:02.017

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap iartist_lite ≤ 1.4.53.1 Yes
Application qnap signage_station ≤ 2.0 Yes

References