CVE-2017-7641: CSRF
Published Mar 8, 2018
·Updated
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Affected Software
4 affected components
QNAP Media Streaming add-on<=430.1.2.0
QNAP QTS=4.3.3
QNAP Media Streaming add-on<=421.1.0.2
QNAP QTS<=4.2.6
Event History
Mar 8, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2017-7641.
2
What is the severity of CVE-2017-7641?
The severity of CVE-2017-7641 is high.
3
Which software versions are affected by CVE-2017-7641?
QNAP NAS application Media Streaming add-on versions 421.1.0.2, 430.1.2.0, and earlier are affected by CVE-2017-7641.
4
Does QNAP QTS version 4.3.3 and earlier have the vulnerability?
No, QNAP QTS version 4.3.3 and earlier are not vulnerable to CVE-2017-7641.
5
How can I mitigate CVE-2017-7641?
Apply the latest patch or upgrade to a non-vulnerable version of QNAP NAS application Media Streaming add-on.