CVE-2018-0728

Severity
7.5HIGH
EPSS
0.3%
top 48.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateMay 24

Description

This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDqnap/helpdesk< 3.0.0
CVEListV5qnap_nas_devicesAll QTS versions: Helpdesk before version 3.0.0

🔴Vulnerability Details

2
GHSA
GHSA-x36q-229j-mv7q: This improper access control vulnerability in Helpdesk allows attackers to access the system logs2022-05-24
CVEList
CVE-2018-0728: This improper access control vulnerability in Helpdesk allows attackers to access the system logs2019-12-04
CVE-2018-0728 (HIGH CVSS 7.5) | This improper access control vulner | cvebase.io