CVE-2017-7638 Vulnerability Details

  /     /     /  

CVE-2017-7638 Metadata Quick Info

CVE Published: 08/03/2018 | CVE Updated: 17/09/2024 | CVE Year: 2017
Source: qnap | Vendor: QNAP | Product: QNAP Media Streaming Add-On
Status : PUBLISHED

CVE-2017-7638 Description

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Incorrect Access Control
Source: QNAP

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).