FTP: QNAP QTS Hard Coded Credential Access

This signature detects attempts to exploit a known vulnerability against QNAP QTS. A successful exploit can lead to remote code execution.

Extended Description

The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.

Affected Products

Qnap signage_station

References

CVE: CVE-2015-7261

Short Name
FTP:AUDIT:QNAP-QTS-HDAC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
FTP
Keywords
Access CVE-2015-7261 Coded Credential Hard QNAP QTS
Release Date
06/05/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Qnap

CVSS Score

7.5

Found a potential security threat?