First published: Thu Dec 21 2017(Updated: )
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <=4.3.3.0378 | |
QNAP QTS | =4.3.4.0358-beta1 | |
QNAP QTS | =4.3.4.0370-beta1 | |
QNAP QTS | =4.3.4.0372-beta1 | |
QNAP QTS | =4.3.4.0374-beta1 | |
QNAP QTS | =4.3.4.0387-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17030 is a critical severity vulnerability that can lead to remote code execution on affected QNAP NAS devices.
To fix CVE-2017-17030, you should update to the latest version of QNAP QTS that addresses this vulnerability.
CVE-2017-17030 affects QNAP QTS versions up to 4.3.3.0378 and several earlier beta versions.
CVE-2017-17030 is a buffer overflow vulnerability in the login function of QNAP QTS.
Yes, CVE-2017-17030 can be exploited remotely by attackers to execute arbitrary code on vulnerable NAS devices.