CVE-2015-6022: Critical severity qnap signage station vulnerability
Published Feb 27, 2016
·Updated
Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL.
Affected Software
1 affected component
QNAP Signage Station<=2.0
Event History
Feb 27, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6022?
CVE-2015-6022 has a medium severity level due to its ability to allow remote code execution.
2
How do I fix CVE-2015-6022?
To fix CVE-2015-6022, upgrade QNAP Signage Station to version 2.0.1 or later.
3
What systems are affected by CVE-2015-6022?
CVE-2015-6022 affects QNAP Signage Station versions prior to 2.0.1.
4
Who can exploit CVE-2015-6022?
CVE-2015-6022 can be exploited by remote authenticated users with the ability to upload files.
5
What type of attack does CVE-2015-6022 facilitate?
CVE-2015-6022 facilitates arbitrary code execution through unrestricted file uploads.