Vulnerability Description
The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Iartist Lite | <= 1.4.53.1 |
| Qnap | Signage Station | <= 2.0 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/444472Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/444472Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-7261?
CVE-2015-7261 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a ...
How severe is CVE-2015-7261?
CVE-2015-7261 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-7261?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Iartist Lite, Qnap Signage Station.