CVE-2017-17027: Buffer Overflow
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17027?
CVE-2017-17027 has a high severity due to the potential for remote code execution on affected QNAP NAS devices.
How do I fix CVE-2017-17027?
To fix CVE-2017-17027, update your QNAP QTS to the latest version that addresses this vulnerability.
Which QNAP QTS versions are affected by CVE-2017-17027?
CVE-2017-17027 affects QNAP QTS versions 4.2.6 build 20171026, 4.3.3.0378 build 20171117, and earlier.
Can CVE-2017-17027 lead to data loss?
Yes, CVE-2017-17027 could potentially lead to data loss since it allows attackers to execute arbitrary code on the device.
Is there a workaround for CVE-2017-17027?
A temporary workaround for CVE-2017-17027 is to disable the FTP service on affected QNAP NAS devices until a patch is applied.