PT-2016-1318 · Qnap · Qnap Iartist Lite+1

Mark Woods

·

Published

2016-02-27

·

Updated

2016-03-11

·

CVE-2015-7261

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNAP Signage Station versions prior to 2.0.1 QNAP iArtist Lite versions prior to 1.4.54
Description The issue exists due to hardcoded registration data in the FTP service of the affected software. This allows a remote attacker to gain access to protected information through a session on TCP port 21.
Recommendations For QNAP Signage Station versions prior to 2.0.1, update to version 2.0.1 or later. For QNAP iArtist Lite versions prior to 1.4.54, update to version 1.4.54 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00617
CVE-2015-7261

Affected Products

Qnap Signage Station
Qnap Iartist Lite