SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0143

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters…

MEDIUM 6.5EPSS 6.97%

Does this matter?

Lower severity and a low EPSS score (6.97%). Track it; it rarely justifies an emergency change on its own.

Description

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
6.97% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
qnap/viostor network video recorder · qnap/surveillance station pro · qnap/nas
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.