QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Information
Published : 2014-08-25 09:55
Updated : 2014-08-26 10:21
NVD link : CVE-2014-5457
Mitre link : CVE-2014-5457
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
qnap
- ss-839
- ts-459u
- ss-839_firmware
- ts-ec1679u-rp
- ts-ec1679u-rp_firmware
- ts-469u_firmware
- ts-469u
- ts-459u_firmware