vendor:
Turbo NAS
by:
Sense of Security
7,5
CVSS
HIGH
Command Injection, Cryptography, Cross-site Scripting
78, 311, 79
CWE
Product Name: Turbo NAS
Affected Version From: Firmware Version: 3.6.1 Build 0302T and prior
Affected Version To: Firmware Version: 3.6.1 Build 0302T and prior
Patch Exists: NO
Related CWE: CVE - not yet assigned
CPE: h:qnap:turbo_nas
Metasploit:
https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28704/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28707/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-28708/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28704/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28707/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-28708/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Verified
2012
Sense of Security – Security Advisory – SOS-12-006
Multiple vulnerabilities have been identified in the web management interface of QNAP. These include Command Injection, Cryptography and Cross-site Scripting. The Command Injection vulnerability exists in the QNAP Download Station (QDownload) as the application executes user-controllable data that is processed by a shell command interpreter. The Cryptography vulnerability exists in the QNAP login page as it stores persistent cookies (including the administrator username and password) as base64 encoded strings inside the cookie parameter nas_p. The Cross-site Scripting vulnerability exists in the web management interface.
Mitigation:
Currently no software update; vendor has elected not to fix at this time