Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 1 of 15
CVE-2014-6271P1CRITICALCVSS 9.8KEVPoCfixed in 4.1.1v4.1.12014-09-24
CVE-2014-6271 [CRITICAL] CWE-78 CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts execute
nvd
CVE-2014-7169P1CRITICALCVSS 9.8KEVPoCfixed in 4.1.1v4.1.12014-09-25
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definiti
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgi
nvd
CVE-2020-2509P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 4.2.6≥ 4.3.5, < 4.3.6+67 more2021-04-17
CVE-2020-2509 [CRITICAL] CWE-77 CVE-2020-2509: A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620
nvd
CVE-2018-19949P1CRITICALCVSS 9.8KEVRansomwarefixed in 4.2.6≥ 4.3.1.0013, < 4.3.3.1161+5 more2020-10-28
CVE-2018-19949 [CRITICAL] CWE-20 CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers to run arbitrary com
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6
nvd
CVE-2019-7193P1CRITICALCVSS 9.8KEVRansomwarev4.3.6.0895v4.3.6.0907+14 more2019-12-05
CVE-2019-7193 [CRITICAL] CWE-20 CVE-2019-7193: This improper input validation vulnerability allows remote attackers to inject arbitrary code to the
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
nvd
CVE-2018-19953P1MEDIUMCVSS 6.1KEVRansomwarefixed in 4.2.6≥ 4.3.1.0013, < 4.3.3.1161+5 more2020-10-28
CVE-2018-19953 [MEDIUM] CWE-79 CVE-2018-19953: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6
nvd
CVE-2018-19943P1MEDIUMCVSS 5.4KEVRansomwarefixed in 4.2.6≥ 4.3.1.0013, < 4.3.3.1252+5 more2020-10-28
CVE-2018-19943 [MEDIUM] CWE-79 CVE-2018-19943: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 b
nvd
CVE-2023-47218P1HIGHCVSS 8.3ExploitedPoC≥ 5.1.0, < 5.1.5.2645v5.1.5.26452024-02-13
CVE-2023-47218 [HIGH] CWE-77 CVE-2023-47218: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QuTS hero h5.1.5.2647 build 20240118 and later
QuTSclou
nvd
CVE-2017-6361P1CRITICALCVSS 9.8ExploitedPoC≤ 4.2.42017-03-23
CVE-2017-6361 [CRITICAL] CWE-78 CVE-2017-6361: QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
nvd
CVE-2017-6360P1CRITICALCVSS 9.8ExploitedPoC≤ 4.2.42017-03-23
CVE-2017-6360 [CRITICAL] CWE-78 CVE-2017-6360: QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain se
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
nvd
CVE-2024-27130P1HIGHCVSS 8.8ExploitedPoCv5.1.0.2348v5.1.0.2399+10 more2024-05-21
CVE-2024-27130 [HIGH] CWE-120 CVE-2024-27130: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network.
We have already fixed the vulnerability in the following version:
QTS 5.1.7.2770 build 20240520 and later
QuTS hero h5.1.7.2770 build 20240520 an
nvd
CVE-2024-21899P1CRITICALCVSS 9.8Exploitedfixed in 4.5.4.2627≥ 5.1.0, < 5.1.3.2578+2 more2024-03-08
CVE-2024-21899 [CRITICAL] CWE-287 CVE-2024-21899: An improper authentication vulnerability has been reported to affect several QNAP operating system v
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231
nvd
CVE-2020-36195P1CRITICALCVSS 9.8ExploitedRansomwarefixed in 4.3.3≥ 4.3.4, < 4.3.6+52 more2021-04-17
CVE-2020-36195 [CRITICAL] CWE-20 CVE-2020-36195: An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or th
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3:
nvd
CVE-2017-7876P1CRITICALCVSS 10.0Exploited≤ 4.2.62017-06-15
CVE-2017-7876 [CRITICAL] CWE-77 CVE-2017-7876: This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compro
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.
nvd
CVE-2023-50358P1MEDIUMCVSS 5.8Exploited≥ 4.2.0, < 4.2.6≥ 4.3.0, < 4.3.3.2644+7 more2024-02-13
CVE-2023-50358 [MEDIUM] CWE-78 CVE-2023-50358: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QTS 4.5.4.2627 build 20231225 and later
QTS 4.3.6.266
nvd
CVE-2023-39296P2HIGHCVSS 7.5Exploitedv5.1.0.2348v5.1.0.2399+5 more2024-01-05
CVE-2023-39296 [HIGH] CWE-1321 CVE-2023-39296: A prototype pollution vulnerability has been reported to affect several QNAP operating system versio
A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 bui
nvd
CVE-2017-6359P2CRITICALCVSS 9.8PoC≤ 4.2.42017-03-23
CVE-2017-6359 [CRITICAL] CWE-78 CVE-2017-6359: QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute a
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
nvd
CVE-2017-13067P2CRITICALCVSS 9.8PoC≥ 4.2.0, ≤ 4.2.6≥ 4.3.0, ≤ 4.3.3.02992017-09-14
CVE-2017-13067 [CRITICAL] CVE-2017-13067: QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versio
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to succe
nvd
CVE-2023-23368P1CRITICALCVSS 9.8v5.0.1v5.0.1.2034+21 more2023-11-03
CVE-2023-23368 [CRITICAL] CWE-78 CVE-2023-23368: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QTS 4.5.4.2374 build 20230416 and later
QuTS hero h
nvd
CVE-2023-23369P2CRITICALCVSS 9.8v5.1.0.2348v4.3.6.0895+57 more2023-11-03
CVE-2023-23369 [CRITICAL] CWE-77 CVE-2023-23369: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.2 ( 2023/05/04 ) and later
Multimedia Console 1.4.8 ( 2023/05/05 ) a
nvd
1 / 15Next →