2.1
CVSSv2

CVE-2014-5457

Published: 25/08/2014 Updated: 26/08/2014
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

Vulnerable Product Search on Vulmon Subscribe to Product

qnap ts-469u_firmware 4.0.7

qnap ts-469u -

qnap ts-ec1679u-rp_firmware 4.0.7

qnap ts-ec1679u-rp -

qnap ts-459u_firmware 4.0.7

qnap ts-459u -

qnap ss-839_firmware 4.0.7

qnap ss-839 -