CVE-2017-7638
Last modified
CVE-2017-7638 is a vulnerability of currently unknown severity. QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Media Streaming Add-On | <= 430.1.2.0 |
| Qnap | Media Streaming Add-On | <= 421.1.0.2 |
References
- https://www.qnap.com/zh-tw/security-advisory/nas-201803-08Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/nas-201803-08Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7638?
How severe is CVE-2017-7638?
How do I fix CVE-2017-7638?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7632Cross-site scripting (XSS) vulnerability in File Station of …
- CVE-2017-7633QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive…
- CVE-2017-7634Cross-site scripting (XSS) vulnerability in QNAP NAS applica…
- CVE-2017-7635QNAP NAS application Proxy Server through version 1.2.0 does…
- CVE-2017-7636Cross-site scripting (XSS) vulnerability in QNAP NAS applica…
- CVE-2017-7637QNAP NAS application Proxy Server through version 1.2.0 allo…
- CVE-2017-7639QNAP NAS application Proxy Server through version 1.2.0 does…
- CVE-2017-7640QNAP NAS application Media Streaming add-on version 421.1.0.…
- CVE-2017-7641QNAP NAS application Media Streaming add-on version 421.1.0.…
- CVE-2017-7642The sudo helper in the HashiCorp Vagrant VMware Fusion plugi…
- CVE-2017-7643Proxifier for Mac before 2.19 allows local users to gain pri…7.8
- CVE-2017-7644The Management Web Interface in Palo Alto Networks PAN-OS be…
Are you affected by CVE-2017-7638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
