SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7638

Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

MEDIUM 6.5EPSS 0.67%

Does this matter?

Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.

Description

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.67% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
qnap/media streaming add-on
Source
security@qnapsecurity.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.