Vulnerability Description
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Viostor Network Video Recorder | 4.0.3 |
| Qnap | Surveillance Station Pro | - |
| Qnap | Nas | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/927644US Government Resource
- http://www.kb.cert.org/vuls/id/927644US Government Resource
FAQ
What is CVE-2013-0143?
CVE-2013-0143 is a vulnerability with a CVSS score of 6.5 (MEDIUM). cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leve...
How severe is CVE-2013-0143?
CVE-2013-0143 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0143?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Viostor Network Video Recorder, Qnap Surveillance Station Pro, Qnap Nas.