CVE-2017-7640: OS Command Injection
Published Mar 8, 2018
·Updated
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Affected Software
4 affected components
QNAP Media Streaming add-on<=430.1.2.0
QNAP QTS=4.3.3
QNAP Media Streaming add-on<=421.1.0.2
QNAP QTS<=4.2.6
Event History
Mar 8, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-7640?
CVE-2017-7640 is a vulnerability in the QNAP NAS application Media Streaming add-on that allows remote attackers to run arbitrary OS commands with root privileges.
2
What is the severity of CVE-2017-7640?
CVE-2017-7640 has a severity rating of 9.8, which is considered critical.
3
Which versions of the QNAP NAS application Media Streaming add-on are affected by CVE-2017-7640?
Versions 421.1.0.2, 430.1.2.0, and earlier of the QNAP NAS application Media Streaming add-on are affected by CVE-2017-7640.
4
How can remote attackers exploit CVE-2017-7640?
Remote attackers can exploit CVE-2017-7640 by running arbitrary OS commands against the system with root privileges.
5
Is the QNAP QTS vulnerable to CVE-2017-7640?
No, the QNAP QTS version 4.3.3 and version 4.2.6 are not vulnerable to CVE-2017-7640.