First published: Fri Feb 01 2019(Updated: )
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | >=5.7.0<=5.7.2 | |
QNAP QTS | =4.3.4 | |
QNAP Photo Station | >=5.4.0<=5.4.4 | |
QNAP QTS | =4.3.3 | |
QNAP Photo Station | >=5.2.0<=5.2.8 | |
QNAP QTS | =4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0722 is a path traversal vulnerability in Photo Station versions 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, and 5.2.8 and earlier in QTS 4.2.6 that could allow remote attackers to access sensitive information on the device.
CVE-2018-0722 affects QNAP Photo Station versions 5.7.2 and earlier, as well as QTS versions 4.3.4, 4.3.3, and 4.2.6.
CVE-2018-0722 has a severity rating of 7.5 (High).
Remote attackers can exploit CVE-2018-0722 by leveraging the path traversal vulnerability to access sensitive information on the device.
You can find more information about CVE-2018-0722 on the QNAP Security Advisory page: https://www.qnap.com/zh-tw/security-advisory/nas-201901-14