Command Injection Vulnerability in QNAP Q'center Virtual Appliance
CVE-2018-0708

8.8HIGH

Key Information:

Vendor
Qnap
Vendor
CVE Published:
17 July 2018

Badges

👾 Exploit Exists🟣 EPSS 17%

Summary

A command injection vulnerability exists in the networking component of the QNAP Q'center Virtual Appliance, affecting version 1.7.1063 and earlier. This issue allows authenticated users to execute arbitrary commands, which poses significant risks to the confidentiality, integrity, and availability of the system. Proper security measures must be implemented to safeguard against potential exploitation of this vulnerability.

Affected Version(s)

Q'center Virtual Appliance 1.7.1063 and earlier

References

EPSS Score

17% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.