Vulnerabilities > CVE-2013-0142 - Credentials Management vulnerability in Qnap products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
qnap
CWE-255

Summary

QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

Vulnerable Configurations

Part Description Count
OS
Qnap
1
Hardware
Qnap
2
Application
Qnap
1

Common Weakness Enumeration (CWE)