CVE-2017-17028: Buffer Overflow
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17028?
CVE-2017-17028 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2017-17028?
To fix CVE-2017-17028, update QNAP QTS to the latest version that is not affected by the vulnerability.
What versions of QNAP QTS are affected by CVE-2017-17028?
CVE-2017-17028 affects QNAP QTS versions up to and including 4.3.3.0378 and several beta builds.
What kind of attack can exploit CVE-2017-17028?
CVE-2017-17028 can be exploited by remote attackers to execute arbitrary code on the affected NAS devices.
What is the nature of the vulnerability in CVE-2017-17028?
CVE-2017-17028 is a buffer overflow vulnerability in the external device function of QNAP QTS.