First published: Thu Mar 08 2018(Updated: )
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Media Streaming Add-on | <=430.1.2.0 | |
QNAP QTS | =4.3.3 | |
Qnap Media Streaming Add-on | <=421.1.0.2 | |
QNAP QTS | <=4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7640 is a vulnerability in the QNAP NAS application Media Streaming add-on that allows remote attackers to run arbitrary OS commands with root privileges.
CVE-2017-7640 has a severity rating of 9.8, which is considered critical.
Versions 421.1.0.2, 430.1.2.0, and earlier of the QNAP NAS application Media Streaming add-on are affected by CVE-2017-7640.
Remote attackers can exploit CVE-2017-7640 by running arbitrary OS commands against the system with root privileges.
No, the QNAP QTS version 4.3.3 and version 4.2.6 are not vulnerable to CVE-2017-7640.