QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 02:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2014/Jul/57 - | |
References | () http://seclists.org/fulldisclosure/2014/Jul/58 - | |
References | () http://seclists.org/fulldisclosure/2014/Jul/59 - | |
References | () http://seclists.org/fulldisclosure/2014/Jul/61 - |
Information
Published : 2014-08-25 16:55
Updated : 2024-11-21 02:12
NVD link : CVE-2014-5457
Mitre link : CVE-2014-5457
CVE.ORG link : CVE-2014-5457
JSON object : View
Products Affected
qnap
- ss-839_firmware
- ts-ec1679u-rp
- ts-469u_firmware
- ts-ec1679u-rp_firmware
- ts-469u
- ss-839
- ts-459u
- ts-459u_firmware
CWE
CWE-264
Permissions, Privileges, and Access Controls