Release date:
Updated on:
Affected Systems:
Thecus NAS Server N8800 5.03.01
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-5667
Thecus NAS server N8800 is a network access server device.
Thecus NAS server N8800 (firmware version 5.03.01) has a security vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary commands by using the username parameter to include the get_userid operation containing metacharacters.
<* Source: David Stubley
Link: http://www.kb.cert.org/vuls/id/105686
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Thecus
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.thecus.com/
Http://www.7elements.co.uk/news/cve-2013-5667
Http://www.7elements.co.uk/news/cve-2013-5668
Http://www.7elements.co.uk/news/cve-2013-5669
Http://www.7elements.co.uk/resources/blog/multiple-vulnerabilities-thecus-nas/