First published: Thu Mar 08 2018(Updated: )
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Media Streaming Add-on | <=430.1.2.0 | |
QNAP QTS | =4.3.3 | |
Qnap Media Streaming Add-on | <=421.1.0.2 | |
QNAP QTS | <=4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7638 is a vulnerability in the QNAP NAS application Media Streaming add-on that allows unauthorized access to sensitive information and the ability to change Media Streaming settings.
The severity of CVE-2017-7638 is medium with a CVSS score of 6.5.
CVE-2017-7638 can affect QNAP NAS devices running Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier, potentially leading to unauthorized access and leakage of sensitive information.
To fix CVE-2017-7638, you should update the QNAP NAS Media Streaming add-on to the latest version available.
You can find more information about CVE-2017-7638 on the QNAP security advisory page at [https://www.qnap.com/zh-tw/security-advisory/nas-201803-08](https://www.qnap.com/zh-tw/security-advisory/nas-201803-08).