CVE-2017-13071
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Affects 2 products across 1 vendor.
Attacker injects operating system commands through application inputs passed to a shell or system call.
Show all 8
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
This vulnerability was disclosed in 2017. A critical vulnerability affects Qnap systems (CVE-2017-13071). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
BSID: BS-2017-GLOBAL-115558-C • Model: rule-based-v1 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2017-13071?
What is the CVSS score for CVE-2017-13071?
Is CVE-2017-13071 actively exploited?
How do I remediate CVE-2017-13071?
What systems are affected by CVE-2017-13071?
| CVE ID | CVE-2017-13071 |
|---|---|
| BSID | BS-2017-GLOBAL-115558-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2017-11-22 |
| Last Modified | 2026-05-13 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Exploitation Likelihood: LOW
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 17011fdbaf594fb3dfbe861b7f47914edd352a10d6a86f338439089c2e77e4791883a8e38d75ed30deac60bebe6772c0a099008d236376531208a049550c89b5 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →