CVE-2013-0143
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters…
Does this matter?
Lower severity and a low EPSS score (6.97%). Track it; it rarely justifies an emergency change on its own.
Description
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 6.97% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- qnap/viostor network video recorder · qnap/surveillance station pro · qnap/nas
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/927644US Government Resource
- http://www.kb.cert.org/vuls/id/927644US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.