CVE-2017-7876criticalobserved exploitation

CVE-2017-7876

Published · Updated

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 10epss 3.3%
from disclosure to weapon
Published on NVDJun 15
VulnCheck+2652d
exploitation probability
3.3%top 12% of all CVEs
observed exploitation
yesVulnCheck
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
n/a · n/a