Vulnerabilities > CVE-2018-14748 - Incorrect Authorization vulnerability in Qnap QTS

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
qnap
CWE-863

Summary

Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.

Vulnerable Configurations

Part Description Count
OS
Qnap
4

Common Weakness Enumeration (CWE)