PT-2018-9033 · Qnap · Qnap Qts+1

Yoni Ramon

·

Published

2018-08-13

·

Updated

2019-10-03

·

CVE-2018-0714

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QNAP QTS versions 4.2.6 build 20180531 and earlier QNAP QTS versions 4.3.3 build 20180528 and earlier QNAP QTS versions 4.3.4 build 20180528 and earlier Helpdesk versions 1.1.21 and earlier
Description A command injection issue could allow remote attackers to run arbitrary commands in the compromised application.
Recommendations For QNAP QTS versions 4.2.6 build 20180531 and earlier, update to a version later than 4.2.6 build 20180531. For QNAP QTS versions 4.3.3 build 20180528 and earlier, update to a version later than 4.3.3 build 20180528. For QNAP QTS versions 4.3.4 build 20180528 and earlier, update to a version later than 4.3.4 build 20180528. For Helpdesk versions 1.1.21 and earlier, update to a version later than 1.1.21.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0714

Affected Products

Helpdesk
Qnap Qts