PT-2016-3702 · Qnap · Qnap Signage Station

Mark Woods

·

Published

2016-02-27

·

Updated

2016-03-08

·

CVE-2015-6022

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNAP Signage Station versions prior to 2.0.1
Description The issue allows remote authenticated users to execute arbitrary code by uploading an executable file and then accessing it via an unspecified URL. This is due to an unrestricted file upload vulnerability.
Recommendations For versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to prevent the execution of arbitrary code.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-6022

Affected Products

Qnap Signage Station