CVE-2015-7262

HIGH

QNAP iArtist Lite <1.4.54 - Privilege Escalation

Title source: llm
STIX 2.1

Description

QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/444472

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-18
Status published
Products (2)
qnap/iartist_lite < 1.4.53.1
qnap/signage_station < 2.0
Published Feb 27, 2016
Tracked Since Feb 18, 2026