Overview
Thecus NAS server N8800 with firmware version 5.03.01, and possibly earlier versions, contains multiple vulnerabilities.
Description
The 7 Elements advisory states that the Thecus NAS server N8800 device contains the following vulnerabilities: CVE-2013-5667 - Thecus NAS Server N8800 Firmware 5.03.01 get_userid OS Command Injection |
Impact
An attacker may be able to execute arbitrary system commands, steal the Domain Administrator credentials, or sniff administrative passwords. |
Solution
Apply an Update |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 9.5 | E:F/RL:U/RC:C |
Environmental | 2.4 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to David Stubley for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2013-5667, CVE-2013-5668, CVE-2013-5669 |
Date Public: | 2014-01-23 |
Date First Published: | 2014-01-23 |
Date Last Updated: | 2014-02-10 17:23 UTC |
Document Revision: | 15 |