CVE-2018-14747: Null Pointer Dereference
Published Nov 28, 2018
·Updated
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
Affected Software
4 affected components
QNAP QTS=4.2.6
QNAP QTS=4.3.3
QNAP QTS=4.3.4
QNAP QTS=4.3.5
Event History
Nov 28, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-14747?
CVE-2018-14747 is considered a medium severity vulnerability due to the potential for remote attackers to crash the NAS media server.
2
How do I fix CVE-2018-14747?
To fix CVE-2018-14747, update QTS to the latest version as recommended by QNAP's security advisory.
3
Which versions of QTS are affected by CVE-2018-14747?
CVE-2018-14747 affects QTS versions 4.2.6, 4.3.3, 4.3.4, and 4.3.5.
4
What type of vulnerability is CVE-2018-14747?
CVE-2018-14747 is classified as a NULL Pointer Dereference vulnerability.
5
What impact does CVE-2018-14747 have on the system?
CVE-2018-14747 can allow remote attackers to crash the NAS media server, leading to denial of service.