// For flags

CVE-2013-0142

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

Los dispositivos QNAP VioStor NVR con firmware v4.0.3, y el componente Surveillance Station Pro en QNAP NAS, tiene una cuenta de invitado incluida en el código que permite que atacantes remotos consigan acceso al servidor web mediante vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-06-07 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
References (1)
URL Tag Source
http://www.kb.cert.org/vuls/id/927644 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qnap
Search vendor "Qnap"
Viostor Network Video Recorder
Search vendor "Qnap" for product "Viostor Network Video Recorder"
4.0.3
Search vendor "Qnap" for product "Viostor Network Video Recorder" and version "4.0.3"
-
Affected
in Qnap
Search vendor "Qnap"
Viostor Network Video Recorder
Search vendor "Qnap" for product "Viostor Network Video Recorder"
--
Affected
Qnap
Search vendor "Qnap"
Surveillance Station Pro
Search vendor "Qnap" for product "Surveillance Station Pro"
--
Affected
Qnap
Search vendor "Qnap"
Nas
Search vendor "Qnap" for product "Nas"
--
Affected