CVE-2017-17029
Summary
| CVE | CVE-2017-17029 |
|---|---|
| State | PUBLISHED |
| Assigner | qnap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-21 15:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.032360000 probability, percentile 0.872280000 (date 2026-05-19)
Problem Types: CWE-119 | Buffer Overflow
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Qnap | Qts | 4.3.4.0358 | beta1 | All | All |
| Operating System | Qnap | Qts | 4.3.4.0370 | beta1 | All | All |
| Operating System | Qnap | Qts | 4.3.4.0372 | beta1 | All | All |
| Operating System | Qnap | Qts | 4.3.4.0374 | beta1 | All | All |
| Operating System | Qnap | Qts | 4.3.4.0387 | beta2 | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | QNAP | QTS Login Function | affected 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Buffer Overflow Vulnerabilities in QTS - Security Advisory | QNAP | af854a3a-2127-422b-91ae-364da2661108 | www.qnap.com | Issue Tracking, Vendor Advisory |
| QNAP Storage Devices Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.