TROYANOSYVIRUS
Back to CVEs

CVE-2014-5457

N/A

Description

QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

CVE Details

CVSS v3.1 ScoreN/A
Published8/25/2014
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

qnap:ss-839qnap:ss-839_firmwareqnap:ts-459uqnap:ts-459u_firmwareqnap:ts-469uqnap:ts-469u_firmwareqnap:ts-ec1679u-rpqnap:ts-ec1679u-rp_firmware

Weaknesses (CWE)

CWE-264

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.