CVE-2017-5227: Infoleak
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP QTSto a version that resolves this vulnerability.Fixed in 4.2.4 Build 20170313
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5227?
CVE-2017-5227 is considered a high severity vulnerability due to the potential exposure of sensitive Domain Administrator password information.
How do I fix CVE-2017-5227?
To fix CVE-2017-5227, upgrade QNAP QTS to version 4.2.4 Build 20170313 or later.
What systems are affected by CVE-2017-5227?
CVE-2017-5227 affects QNAP QTS versions prior to 4.2.4 Build 20170313.
What type of attack does CVE-2017-5227 facilitate?
CVE-2017-5227 facilitates local attacks where users can read sensitive configuration data in the /etc/config/uLinux.conf file.
Who can exploit CVE-2017-5227?
Local users with access to the system can exploit CVE-2017-5227 to retrieve sensitive password information.