CVE Vulnerabilities

CVE-2018-14747

NULL Pointer Dereference

Published: Nov 28, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Qts Qnap 4.2.6 (including) 4.2.6 (including)
Qts Qnap 4.3.3 (including) 4.3.3 (including)
Qts Qnap 4.3.4 (including) 4.3.4 (including)
Qts Qnap 4.3.5 (including) 4.3.5 (including)

Potential Mitigations

References