PT-2018-8409 · Qnap · Qts
Published
2018-03-27
·
Updated
2018-04-18
·
CVE-2017-7630
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP QTS versions 4.2.6 build 20171026 and earlier, QTS 4.3.3 build 20170727 and earlier
Description
The issue allows remote attackers to obtain potentially sensitive information, such as the firmware version and running services, via a request to "sysinfoReq.cgi".
Recommendations
For QNAP QTS versions 4.2.6 build 20171026 and earlier, restrict access to the "sysinfoReq.cgi" endpoint to minimize the risk of exploitation.
For QTS 4.3.3 build 20170727 and earlier, consider disabling the
sysinfoReq.cgi endpoint until a patch is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qts