CVE-2014-5457
Published Aug 25, 2014
Last updated 10 years ago
Overview
- Description
- QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:qnap:ts-469u_firmware:4.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2B65BB8-4B24-48A4-90A7-FAE5C5E260DB" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:qnap:ts-469u:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "331E1B35-C5FD-44B5-9827-157D35ACB2C5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:qnap:ts-ec1679u-rp_firmware:4.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BEA901D-BB92-4D55-A6FD-70131F041A55" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:qnap:ts-ec1679u-rp:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C58E082B-988F-4F52-AE3D-97278E30B2DF" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:qnap:ts-459u_firmware:4.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6199EB5-BBC8-4458-BCFE-08E81854CECF" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:qnap:ts-459u:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2780069E-B319-46B8-AD58-A2E64E08F356" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:qnap:ss-839_firmware:4.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3016E6EB-D391-43D2-8C34-CEAA53DD2D7D" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:qnap:ss-839:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FFDFCF4-A1FC-407D-AB69-011157AA99DC" } ], "operator": "OR" } ], "operator": "AND" } ]