Qnap QTS Path Traversal (CVE-2015-6003)

high Tenable OT Security Plugin ID 502502

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://www.qnap.com/i/en/support/con_show.php?cid=85

http://www.kb.cert.org/vuls/id/751328

http://www.securitytracker.com/id/1033794

Plugin Details

Severity: High

ID: 502502

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 10/16/2024

Updated: 10/16/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-6003

Vulnerability Information

CPE: cpe:/o:qnap:qts

Required KB Items: Tenable.ot/Qnap

Exploit Ease: No known exploits are available

Patch Publication Date: 10/16/2015

Vulnerability Publication Date: 10/16/2015

Reference Information

CVE: CVE-2015-6003

CWE: 22