CVE-2017-13071: Command Injection
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-13071?
CVE-2017-13071 is a security vulnerability that allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Has QNAP patched CVE-2017-13071?
Yes, QNAP has already patched this vulnerability.
What is the severity of CVE-2017-13071?
The severity of CVE-2017-13071 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2017-13071?
QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier versions are affected by CVE-2017-13071.
Where can I find more information about CVE-2017-13071?
You can find more information about CVE-2017-13071 in the QNAP security advisory at https://www.qnap.com/zh-tw/security-advisory/nas-201711-21.