2.1

CVE-2014-5457

QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

Data is provided by the National Vulnerability Database (NVD)
QnapTs-469u Firmware Version4.0.7
QnapTs-469u Version-
QnapTs-ec1679u-rp Firmware Version4.0.7
QnapTs-ec1679u-rp Version-
QnapTs-459u Firmware Version4.0.7
QnapTs-459u Version-
QnapSs-839 Firmware Version4.0.7
QnapSs-839 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.132
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N