CVE-2017-12582
Summary
| CVE | CVE-2017-12582 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-18 16:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qnap | Ts-212p | - | All | All | All |
| Hardware | Qnap | Ts-212p | - | All | All | All |
| Operating System | Qnap | Ts-212p Firmware | 4.2.1 | All | All | All |
| Operating System | Qnap | Ts-212p Firmware | 4.2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KTH Ninja: QNAP Surveillance station Authentication Bypass | MISC | www.kth.ninja | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.