CVE-2018-0714: Command Injection
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0714?
CVE-2018-0714 is a command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions.
What is the severity of CVE-2018-0714?
CVE-2018-0714 has a severity rating of 9.8, which is considered critical.
How can remote attackers exploit CVE-2018-0714?
Remote attackers can exploit CVE-2018-0714 by running arbitrary commands in the compromised Helpdesk application.
Which versions of QNAP QTS are affected by CVE-2018-0714?
The affected versions of QNAP QTS are 4.2.6 build 20180531, 4.3.3 build 20180528, and 4.3.4 build 20180528, and their earlier versions.
How can I fix CVE-2018-0714?
To fix CVE-2018-0714, update to the latest version of Helpdesk and QNAP QTS.