HTTP: QNAP Qcenter Virtual Appliance Multiple CVE's Remote Code Execution

This signature detects attempts to exploit a known vulnerability against QNAP Qcenter Virtual Appliance. A successful attack can lead to arbitrary code execution.

Extended Description

Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.

Affected Products

Qnap q'center

Short Name
HTTP:STC:QNAP-MULTIPLE-RCE-CVE
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Appliance CVE's CVE-2018-0706 CVE-2018-0707 CVE-2018-0708 CVE-2018-0709 CVE-2018-0710 Code Execution Multiple QNAP Qcenter Remote Virtual
Release Date
03/05/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3693
False Positive
Unknown
Vendors

Qnap

CVSS Score

9.0

4.0

Found a potential security threat?