OS command execution in QNAP Proxy Server - CVE-2017-7637
Published: June 6, 2018
Vulnerability identifier: #VU13191
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7637
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute shell commands on the target system.
The weakness exists due to incorrect processing of the user’s input data in the certain parameter. A remote attacker can inject and execute arbitrary shell commands with root privileges.
The weakness exists due to incorrect processing of the user’s input data in the certain parameter. A remote attacker can inject and execute arbitrary shell commands with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
QNAP Proxy Server
How to mitigate CVE-2017-7637
Update to version 1.2.1. or 1.3.0.
QNAP Proxy Server - addressed in versions 1.2.1, 1.3.0