CVE-2017-7638
published 2018-03-08CVE-2017-7638: QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could…
PriorityP429medium6.5CVSS 3.0
AVNACLPRNUINSUCLILAN
EPSS
0.68%
48.4th percentile
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | media_streaming_add-on | <= 430.1.2.0 | — |
| qnap | media_streaming_add-on | <= 421.1.0.2 | — |
| qnap | qnap_media_streaming_add-on | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jm5g-5386-4p5f: QNAP NAS application Media Streaming add-on version 421
ghsa_unreviewed·2022-05-14
CVE-2017-7638 [MEDIUM] CWE-287 GHSA-jm5g-5386-4p5f: QNAP NAS application Media Streaming add-on version 421
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
OSV
SDL 2.0 vulnerabilities
osv·2019-09-30·CVSS 8.8
CVE-2017-2888 SDL 2.0 vulnerabilities
SDL 2.0 vulnerabilities
It was discovered that SDL 2.0 mishandled crafted image files resulting in an
integer overflow. If a user were tricked into opening a malicious file, SDL
2.0 could be caused to crash or potentially run arbitrary code.
(CVE-2017-2888)
It was discovered that SDL 2.0 mishandled crafted image files. If a user were
tricked into opening a malicious file, SDL 2.0 could be caused to crash or
potentially run arbitrary code.
(CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-08
Published