PT-2018-8409 · Qnap · Qts
Publicado
2018-03-27
·
Atualizado
2018-04-18
·
CVE-2017-7630
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP QTS versions 4.2.6 build 20171026 and earlier, QTS 4.3.3 build 20170727 and earlier
Description
The issue allows remote attackers to obtain potentially sensitive information, such as the firmware version and running services, via a request to "sysinfoReq.cgi".
Recommendations
For QNAP QTS versions 4.2.6 build 20171026 and earlier, restrict access to the "sysinfoReq.cgi" endpoint to minimize the risk of exploitation.
For QTS 4.3.3 build 20170727 and earlier, consider disabling the
sysinfoReq.cgi endpoint until a patch is available.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qts