Vulnerability Description
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Qts | 4.2.6 |
Related Weaknesses (CWE)
References
- https://www.qnap.com/zh-tw/security-advisory/nas-201803-23Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/nas-201803-23Vendor Advisory
FAQ
What is CVE-2017-7630?
CVE-2017-7630 is a vulnerability with a CVSS score of 5.3 (MEDIUM). QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfo...
How severe is CVE-2017-7630?
CVE-2017-7630 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7630?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Qts.