CVE-2018-0728: High severity qnap qts helpdesk vulnerability
Published Dec 4, 2019
·Updated
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
Affected Software
2 affected components
QNAP Helpdesk<3.0.0
QNAP QTS
Event History
Dec 4, 2019
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0728?
CVE-2018-0728 is classified as a high severity vulnerability due to improper access control in Helpdesk.
2
How do I fix CVE-2018-0728?
To fix CVE-2018-0728, it is recommended to update QTS and Helpdesk to their latest versions as provided by QNAP.
3
Which software is affected by CVE-2018-0728?
CVE-2018-0728 affects versions of QNAP Helpdesk prior to 3.0.0.
4
Can CVE-2018-0728 lead to data breaches?
Yes, CVE-2018-0728 can potentially allow attackers to access sensitive system logs, leading to data breaches.
5
Is QTS vulnerable to CVE-2018-0728?
No, QTS itself is not listed as vulnerable in CVE-2018-0728, only the Helpdesk application is affected.