CVE-2018-0709: Command Injection
Published Jul 16, 2018
·Updated
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
Affected Software
1 affected component
QNAP Q\'center<=1.7.1063
Event History
Jul 16, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0709?
CVE-2018-0709 is rated as a high severity vulnerability due to its potential for arbitrary command execution.
2
How do I fix CVE-2018-0709?
To mitigate CVE-2018-0709, update the QNAP Q'center Virtual Appliance to version 1.7.1064 or later.
3
Who is affected by CVE-2018-0709?
Authenticated users of QNAP Q'center Virtual Appliance versions 1.7.1063 and earlier are affected by CVE-2018-0709.
4
What type of vulnerability is CVE-2018-0709?
CVE-2018-0709 is a command injection vulnerability that allows execution of arbitrary commands.
5
What versions are vulnerable to CVE-2018-0709?
Versions of QNAP Q'center Virtual Appliance up to and including 1.7.1063 are vulnerable to CVE-2018-0709.