CVE-2017-10700
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://www.qnap.com/en/support/con_show.php?cid=128
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.