CVE-2017-17031: Buffer Overflow
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17031?
CVE-2017-17031 is considered a critical vulnerability due to its potential to allow remote code execution on affected QNAP NAS devices.
How do I fix CVE-2017-17031?
To fix CVE-2017-17031, users should update their QNAP QTS to the latest version that mitigates the vulnerability.
What are the affected versions for CVE-2017-17031?
CVE-2017-17031 affects QNAP QTS versions 4.2.6 build 20171026, 4.3.3.0378 build 20171117, and all 4.3.4 beta versions before 4.3.4.0387.
Can CVE-2017-17031 be exploited remotely?
Yes, CVE-2017-17031 can be exploited remotely, allowing attackers to execute arbitrary code without physical access to the NAS.
What devices are impacted by CVE-2017-17031?
CVE-2017-17031 impacts QNAP NAS devices running vulnerable versions of the QTS operating system.