Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2024-02758

Опубликовано: 10 окт. 2023
Источник: fstec
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Уязвимость кросс-платформенный BitTorrent клиента qBittorrent связана с использованием учетных данных по умолчанию, когда веб-интерфейс пользователя включен. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольные команды

Вендор

ООО «Ред Софт»
Christophe Dumez
ООО «РусБИТех-Астра»
АО «НППКТ»

Наименование ПО

РЕД ОС
qBittorrent
Astra Linux Special Edition
ОСОН ОСнова Оnyx

Версия ПО

7.3 (РЕД ОС)
до 4.5.5 включительно (qBittorrent)
1.8 (Astra Linux Special Edition)
4.8 (Astra Linux Special Edition)
до 2.15 (ОСОН ОСнова Оnyx)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.8
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.8
АО «НППКТ» ОСОН ОСнова Оnyx до 2.15

Уровень опасности уязвимости

Критический уровень опасности (базовая оценка CVSS 2.0 составляет 10)
Критический уровень опасности (базовая оценка CVSS 3.0 составляет 9,8)

Возможные меры по устранению уязвимости

Для qbittorrent:
https://github.com/qbittorrent/qBittorrent/issues/18731
https://vulncheck.com/advisories/qbittorrent-default-creds
Для РедОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Для ОС Astra Linux:
обновить пакет qbittorrent до 4.5.2-3+deb12u1.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0806SE48
Для ОС Astra Linux:
обновить пакет qbittorrent до 4.5.2-3+deb12u1.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0626SE18
Для ОС Astra Linux:
обновить пакет qbittorrent до 4.5.2-3+deb12u1.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0626SE18
Для ОСОН ОСнова Оnyx: Обновление программного обеспечения qbittorrent до версии 4.2.5+repack-0.1osnova2u1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 58%
0.00908
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Связанные уязвимости

CVSS3: 9.8
redos
больше 2 лет назад

Уязвимость qbittorrent

CVSS3: 9.8
ubuntu
почти 3 года назад

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

CVSS3: 9.8
nvd
почти 3 года назад

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

CVSS3: 9.8
debian
почти 3 года назад

All versions of the qBittorrent client through 4.5.5 use default crede ...

suse-cvrf
почти 3 года назад

Security update for libtorrent-rasterbar, qbittorrent

EPSS

Процентиль: 58%
0.00908
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2