Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-1522 Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2024-09-17T00:01:44.059Z

Reserved: 2017-11-28T00:00:00

Link: CVE-2018-0712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-21T13:29:00.443

Modified: 2024-11-21T03:38:47.967

Link: CVE-2018-0712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.