First published: Tue Sep 19 2017(Updated: )
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =4.3.3.0229 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10700 has a critical severity rating due to its ability to allow unauthenticated attackers to execute arbitrary system commands.
To fix CVE-2017-10700, update your QNAP NAS to a patched version beyond 4.3.3.0229 as provided by QNAP.
CVE-2017-10700 affects the QNAP QTS version 4.3.3.0229.
Yes, CVE-2017-10700 can be exploited remotely by an unauthenticated attacker.
CVE-2017-10700 allows attackers to execute arbitrary system commands as the root user on vulnerable QNAP NAS devices.