Overview
QNAP VioStor NVR firmware version 4.0.3 and possibly earlier versions and QNAP NAS contains multiple vulnerabilities which may allow an attacker to perform administrative functions against the hosted server.
Description
QNAP VioStor NVR firmware version 4.0.3 and possibly earlier versions and QNAP NAS with the Surveillance Station Pro activated contains multiple vulnerabilities which may allow an attacker to perform administrative functions against the hosted server. CWE-284: Improper Access Control CVE-2013-0142 |
Impact
An authenticated (via known credentials or hardcoded guest account) attacker may be able to execute arbitrary commands or add administrative accounts to the server. |
Solution
Update |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 7.7 | E:U/RL:ND/RC:UC |
Environmental | 1.9 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://www.qnapsecurity.com/AboutQNAP.asp
- http://cwe.mitre.org/data/definitions/77.html
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/284.html
- http://www.qnap.com/en/index.php?lang=en&sn=845&c=2699&sc=&n=18922
- http://www.qnap.com/en/index.php?lang=en&sn=845&c=2699&sc=&n=18925
Acknowledgements
Thanks to Tim Herres and David Elze of Daimler TSS for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-0142, CVE-2013-0143, CVE-2013-0144 |
Date Public: | 2013-06-05 |
Date First Published: | 2013-06-05 |
Date Last Updated: | 2014-07-30 16:28 UTC |
Document Revision: | 33 |