First published: Tue Nov 27 2018(Updated: )
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =4.2.6 | |
QNAP QTS | =4.3.3 | |
QNAP QTS | =4.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0721 is classified as a high-severity buffer overflow vulnerability.
To fix CVE-2018-0721, update your QTS to version 4.3.4 or later.
CVE-2018-0721 affects QNAP QTS versions 4.2.6, 4.3.3, and 4.3.4 prior to specific builds.
CVE-2018-0721 allows attackers to execute arbitrary code on affected NAS devices.
Yes, attackers can exploit CVE-2018-0721 through crafted inputs that trigger a buffer overflow.