CVE-2017-7630: Infoleak
Published Mar 27, 2018
·Updated
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
Affected Software
2 affected components
QNAP QTS=4.2.6
QNAP QTS=4.3.3
Event History
Mar 27, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7630?
CVE-2017-7630 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2017-7630?
To mitigate CVE-2017-7630, update your QNAP QTS firmware to the latest version available.
3
What information can be exposed by CVE-2017-7630?
CVE-2017-7630 can expose sensitive information such as the firmware version and running services on the device.
4
Which versions of QNAP QTS are affected by CVE-2017-7630?
CVE-2017-7630 affects QNAP QTS versions 4.2.6 build 20171026, 4.3.3 build 20170727, and earlier.
5
Are remote attackers able to exploit CVE-2017-7630?
Yes, remote attackers can exploit CVE-2017-7630 to obtain sensitive information from vulnerable QNAP devices.