Vulnerability Name: | CVE-2013-0143 (CCN-84772) | ||||||||
Assigned: | 2012-12-06 | ||||||||
Published: | 2013-06-05 | ||||||||
Updated: | 2013-06-10 | ||||||||
Summary: | cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:UR)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-0143 Source: CCN Type: SA53583 QNAP VioStor NVR Cross-Site Request Forgery Vulnerability Source: CCN Type: SA53721 QNAP VioStor NVR and QNAP NAS Products Security Bypass Security Issue and Arbitrary Command Injection Vulnerability Source: CCN Type: US-CERT VU#927644 QNAP VioStor NVR firmware version 4.0.3 and QNAP NAS multiple vulnerabilities Source: CERT-VN Type: US Government Resource VU#927644 Source: CCN Type: QNAP Web site VioStor and NAS Source: CCN Type: BID-60354 QNAP VioStor NVR and QNAP NAS CVE-2013-0143 Remote Code Execution Vulnerability Source: XF Type: UNKNOWN viostor-cve20130143-code-exec(84772) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
BACK |