OS command execution in QNAP Proxy Server - CVE-2017-7637

 

OS command execution in QNAP Proxy Server - CVE-2017-7637

Published: June 6, 2018


Vulnerability identifier: #VU13191
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7637
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute shell commands on the target system.

The weakness exists due to incorrect processing of the user’s input data in the certain parameter. A remote attacker can inject and execute arbitrary shell commands with root privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

QNAP Proxy Server

How to mitigate CVE-2017-7637

Update to version 1.2.1. or 1.3.0.

QNAP Proxy Server - addressed in versions 1.2.1, 1.3.0

External References

Related Security Bulletins