VulnerabilityModified
CVE-2017-7639
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly.
MEDIUM 5.3EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- qnap/nas proxy server
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1041025Third Party Advisory, VDB Entry
- https://www.qnap.com/en/security-advisory/nas-201806-01Vendor Advisory
- http://www.securitytracker.com/id/1041025Third Party Advisory, VDB Entry
- https://www.qnap.com/en/security-advisory/nas-201806-01Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.