97059vdb entry
http://www.securityfocus.com/bid/97059 CVE-2017-6359
CRITICAL
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
Record summary
CVE-2017-6359 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQNAP TVS-663 QTS < 4.2.4 build 20170313 - Command InjectionExploitDB exploitby Harry SintonenNot analyzed1 file
References
797072vdb entry
http://www.securityfocus.com/bid/97072 1038091vdb entry
http://www.securitytracker.com/id/1038091 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6359 41842exploit
https://www.exploit-db.com/exploits/41842 qnap.comConfirmation
https://www.qnap.com/en-us/releasenotes qnap.comConfirmation
https://www.qnap.com/en/support/con_show.php?cid=113