PT-2016-3702 · Qnap · Qnap Signage Station

Mark Woods

·

Publicado

2016-02-27

·

Atualizado

2016-03-08

·

CVE-2015-6022

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNAP Signage Station versions prior to 2.0.1
Description The issue allows remote authenticated users to execute arbitrary code by uploading an executable file and then accessing it via an unspecified URL. This is due to an unrestricted file upload vulnerability.
Recommendations For versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to prevent the execution of arbitrary code.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2015-6022

Produtos afetados

Qnap Signage Station