CVE-2017-7639

MEDIUM

QNAP NAS Proxy Server < 1.3.0 - Improper Authentication

Title source: llm
STIX 2.1

Description

QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.qnap.com/en/security-advisory/nas-201806-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041025

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (1)
qnap/nas_proxy_server < 1.3.0
Published Jun 05, 2018
Tracked Since Feb 18, 2026