CVE-2017-13067
https://notcve.org/view.php?id=CVE-2017-13067
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack. QNAP ha parcheado una vulnerabilidad de ejecución remota de código que afecta a la biblioteca multimedia de QTS en todas sus versiones anteriores a la QTS 4.2.6 build 20170905 y QTS 4.3.3.0299 build 20170901. Esta vulnerabilidad permite que un atacante remoto ejecute comandos en un NAS de QNAP utilizando un servicio de transcodificación en el puerto 9251. • https://www.qnap.com/zh-hk/releasenotes •
CVE-2017-12582
https://notcve.org/view.php?id=CVE-2017-12582
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station. Un usuario sin privilegios podría acceder a todas las funciones en el componente Surveillance Station en los dispositivos QNAP TS212P con firmware 4.2.1 versión 20160601. Un usuario sin privilegios no puede iniciar sesión en el front-end pero con esa SID de usuario sin privilegios, se podría acceder a todas las funciones de Surveillance Station. • http://www.kth.ninja/2017/08/qnap-surveillance-station.html • CWE-862: Missing Authorization •
CVE-2017-7629
https://notcve.org/view.php?id=CVE-2017-7629
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function. QNAP QTS anterior a versión 4.2.6, build 20170517, presenta un fallo en la función change password. • https://www.qnap.com/en-us/releasenotes • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2017-7876
https://notcve.org/view.php?id=CVE-2017-7876
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions. Esta vulnerabilidad de inyección de comandos en el QTS permite a los atacantes ejecutar comandos arbitrarios en la aplicación comprometida. QNAP ya ha solucionado el problema en QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 y versiones posteriores • https://www.qnap.com/en/release-notes/qts/4.2.6/20170517 https://www.qnap.com/en/release-notes/qts/4.3.3.0174/20170503 https://www.qnap.com/zh-tw/security-advisory/nas-201707-12 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2017-6360 – QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
https://notcve.org/view.php?id=CVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. QNAP QTS en versiones anteriores a 4.2.4 revisión 20170313 permite a atacantes obtener información sensible a través de vectores no especificados. QNAP QTS suffers from multiple command injection vulnerabilities. • https://www.exploit-db.com/exploits/41842 http://www.securityfocus.com/bid/97059 http://www.securityfocus.com/bid/97072 http://www.securitytracker.com/id/1038091 https://www.qnap.com/en-us/releasenotes https://www.qnap.com/en/support/con_show.php?cid=113 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •