VYPR
Critical severity9.8NVD Advisory· Published Dec 21, 2017· Updated May 13, 2026

CVE-2017-17033

CVE-2017-17033

Description

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

Affected products

7
  • Qnap/Qts6 versions
    cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: <=4.3.3.0378
    • cpe:2.3:o:qnap:qts:4.3.4.0358:beta1:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.4.0370:beta1:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.4.0372:beta1:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.4.0374:beta1:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.4.0387:beta2:*:*:*:*:*:*
  • QNAP/QTS Notification functionv5
    Range: 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.