Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7638


QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.


Published

2018-03-08T14:29:00.410

Last Modified

2024-11-21T03:32:20.953

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap media_streaming_add-on ≤ 430.1.2.0 Yes
Operating System qnap qts 4.3.3 No
Application qnap media_streaming_add-on ≤ 421.1.0.2 Yes
Operating System qnap qts ≤ 4.2.6 No

References