6.5
CVE-2017-7638
- EPSS 0.19%
- Veröffentlicht 08.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:20
- Quelle security@qnapsecurity.com.tw
- Teams Watchlist Login
- Unerledigt Login
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Media Streaming Add-on Version <= 430.1.2.0
Qnap ≫ Media Streaming Add-on Version <= 421.1.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.373 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.