PT-2021-20474 · Qnap · Media Streaming Add-On
Tony Martin
·
Published
2021-10-22
·
Updated
2022-04-25
·
CVE-2021-34362
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Media Streaming add-on versions prior to 500.0.0.3
Media Streaming add-on versions prior to 430.1.8.12
Description:
A command injection issue has been reported, allowing remote attackers to run arbitrary commands on QNAP devices running the Media Streaming add-on.
Recommendations:
For Media Streaming add-on versions prior to 500.0.0.3, update to version 500.0.0.3 or later.
For Media Streaming add-on versions prior to 430.1.8.12, update to version 430.1.8.12 or later.
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Media Streaming Add-On