First published: Thu Dec 21 2017(Updated: )
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <=4.3.3.0378 | |
QNAP QTS | =4.3.4.0358-beta1 | |
QNAP QTS | =4.3.4.0370-beta1 | |
QNAP QTS | =4.3.4.0372-beta1 | |
QNAP QTS | =4.3.4.0374-beta1 | |
QNAP QTS | =4.3.4.0387-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17027 has a high severity due to the potential for remote code execution on affected QNAP NAS devices.
To fix CVE-2017-17027, update your QNAP QTS to the latest version that addresses this vulnerability.
CVE-2017-17027 affects QNAP QTS versions 4.2.6 build 20171026, 4.3.3.0378 build 20171117, and earlier.
Yes, CVE-2017-17027 could potentially lead to data loss since it allows attackers to execute arbitrary code on the device.
A temporary workaround for CVE-2017-17027 is to disable the FTP service on affected QNAP NAS devices until a patch is applied.