First published: Mon Aug 25 2014(Updated: )
QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Ts-469u Firmware | =4.0.7 | |
QNAP TS-469U | ||
Qnap Ts-ec1679u-rp Firmware | =4.0.7 | |
Qnap Ts-ec1679u-rp | ||
Qnap Ts-459u Firmware | =4.0.7 | |
Qnap Ts-459u | ||
Qnap Ss-839 Firmware | =4.0.7 | |
Qnap Ss-839 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.