PT-2017-12906 · Qnap · Qnap Qts
Published
2017-09-14
·
Updated
2019-10-03
·
CVE-2017-13067
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QNAP QTS versions prior to 4.2.6 build 20170905
QNAP QTS versions prior to 4.3.3.0299 build 20170901
Description
The issue allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.
Recommendations
For QNAP QTS versions prior to 4.2.6 build 20170905, update to QTS 4.2.6 build 20170905 or later.
For QNAP QTS versions prior to 4.3.3.0299 build 20170901, update to QTS 4.3.3.0299 build 20170901 or later.
As a temporary workaround, consider restricting access to the transcoding service on port 9251 until a patch is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnap Qts