Skip to main content

QNAP NAS Remote Code Execution Vulnerability

Last Update Date: 19 Sep 2017 09:31 Release Date: 19 Sep 2017 3538 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in QNAP NAS which could allow a remote user to execute commands without requiring any privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • QTS 4.2.x before QTS 4.2.6 build 20170905
  • QTS 4.3.x before QTS 4.3.3.0299 build 20170901

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to a fixed version (QTS 4.2.6 build 20170905, QTS 4.3.3.0299 build 20170901)

Vulnerability Identifier


Source


Related Link