CVE-2015-7261: Critical severity qnap iartist lite vulnerability
Published Feb 27, 2016
·Updated
The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.
Affected Software
2 affected components
QNAP iArtist Lite<=1.4.53.1
QNAP Signage Station<=2.0
Event History
Feb 27, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7261?
CVE-2015-7261 is considered a high-severity vulnerability due to the presence of hardcoded credentials in the FTP service.
2
How do I fix CVE-2015-7261?
To fix CVE-2015-7261, upgrade QNAP iArtist Lite to version 1.4.54 or later and QNAP Signage Station to version 2.0.1 or later.
3
What are the affected versions of QNAP iArtist Lite in CVE-2015-7261?
QNAP iArtist Lite versions prior to 1.4.54 are affected by CVE-2015-7261.
4
What are the affected versions of QNAP Signage Station in CVE-2015-7261?
QNAP Signage Station versions prior to 2.0.1 are affected by CVE-2015-7261.
5
Can CVE-2015-7261 lead to unauthorized access?
Yes, CVE-2015-7261 allows remote attackers to gain unauthorized access via the FTP service using hardcoded credentials.