CVE-2017-6360: OS Command Injection
Published Mar 23, 2017
·Updated
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
QNAP QTS<=4.2.4
Event History
Mar 23, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6360?
CVE-2017-6360 has a medium severity rating, allowing attackers to gain administrator privileges.
2
How do I fix CVE-2017-6360?
To fix CVE-2017-6360, update QNAP QTS to version 4.2.4 Build 20170313 or later.
3
What can attackers do with CVE-2017-6360?
Attackers exploiting CVE-2017-6360 can gain administrator privileges and access sensitive information.
4
Which versions of QNAP QTS are affected by CVE-2017-6360?
CVE-2017-6360 affects QNAP QTS versions prior to 4.2.4 Build 20170313.
5
Is there a workaround for CVE-2017-6360?
There is no official workaround for CVE-2017-6360; the only mitigation is to upgrade to a patched version.