CVE-2017-12582

UnknownEPSS 1.10%

Last modified

CVE-2017-12582 is a vulnerability of currently unknown severity. Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.

Description

Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.

Metrics

EPSS Probability
1.10%

61.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QnapTs-212p Firmware4.2.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-12582?
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.
How severe is CVE-2017-12582?
Severity scoring for CVE-2017-12582 is pending analysis. The EPSS model estimates a 1.10% probability of exploitation in the next 30 days.
How do I fix CVE-2017-12582?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-12582?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST