Back

CVE-2017-17033

CRITICAL

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

Published: Dec 21, 2017 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
qnap qts *
qnap qts 4.3.4.0358
qnap qts 4.3.4.0370
qnap qts 4.3.4.0372
qnap qts 4.3.4.0374
qnap qts 4.3.4.0387

GitHub Security Advisory GHSA-pmhm-4qjx-4cwf

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4...

References (4)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.44%

Top 9% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub