QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2014-08-25 16:55
Updated : 2024-02-28 12:20
NVD link : CVE-2014-5457
Mitre link : CVE-2014-5457
CVE.ORG link : CVE-2014-5457
JSON object : View
Products Affected
qnap
- ts-469u_firmware
- ts-ec1679u-rp
- ts-ec1679u-rp_firmware
- ts-469u
- ts-459u_firmware
- ss-839_firmware
- ts-459u
- ss-839
CWE
CWE-264
Permissions, Privileges, and Access Controls