Qnap Qts vulnerabilities

272 known vulnerabilities affecting qnap/qts.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
8
Exploited in wild
10
Severity breakdown
CRITICAL39HIGH90MEDIUM106LOW37

Vulnerabilities

Page 13 of 14
CVE-2018-14749CRITICALCVSS 9.8v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14749 [CRITICAL] CWE-119 CVE-2018-14749: Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.
nvd
CVE-2018-14746CRITICALCVSS 9.8v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14746 [CRITICAL] CWE-77 CVE-2018-14746: Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 bui Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
nvd
CVE-2018-14747HIGHCVSS 7.5v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14747 [HIGH] CWE-476 CVE-2018-14747: NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4. NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
nvd
CVE-2018-14748HIGHCVSS 7.5v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14748 [HIGH] CWE-863 CVE-2018-14748: Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3. Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
nvd
CVE-2018-0721HIGHCVSS 7.7v4.2.6v4.3.3+1 more2018-11-27
CVE-2018-0721 [HIGH] CWE-120 CVE-2018-0721: Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
nvd
CVE-2018-0719MEDIUMCVSS 5.5v4.2.6v4.3.3+1 more2018-11-27
CVE-2018-0719 [MEDIUM] CWE-79 CVE-2018-0719: Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
nvd
CVE-2018-0712CRITICALCVSS 9.8v4.2.6v4.3.3+1 more2018-06-21
CVE-2018-0712 [CRITICAL] CWE-77 CVE-2018-0712: Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 201 Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
nvd
CVE-2017-13072MEDIUMCVSS 6.1v4.2.6v4.3.3+1 more2018-06-21
CVE-2017-13072 [MEDIUM] CWE-79 CVE-2017-13072: Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 b Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
nvd
CVE-2018-0711MEDIUMCVSS 6.1v4.3.3.0514v4.3.3.0546+11 more2018-04-30
CVE-2018-0711 [MEDIUM] CWE-79 CVE-2018-0711: Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
cvelistv5nvd
CVE-2017-7631MEDIUMCVSS 6.1v4.2.6v4.3.32018-03-27
CVE-2017-7631 [MEDIUM] CWE-79 CVE-2017-7631: Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 bu Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2017-7630MEDIUMCVSS 5.3v4.2.6v4.3.32018-03-27
CVE-2017-7630 [MEDIUM] CWE-200 CVE-2017-7630: QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtai QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
nvd
CVE-2017-7632MEDIUMCVSS 6.1v4.2.6v4.3.32018-03-27
CVE-2017-7632 [MEDIUM] CWE-79 CVE-2017-7632: Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2017-17033CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17033 [CRITICAL] CWE-119 CVE-2017-17033: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17028CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17028 [CRITICAL] CWE-119 CVE-2017-17028: A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026 A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17029CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17029 [CRITICAL] CWE-119 CVE-2017-17029: A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.03 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17030CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17030 [CRITICAL] CWE-119 CVE-2017-17030: A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.03 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17032CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17032 [CRITICAL] CWE-119 CVE-2017-17032: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17031CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17031 [CRITICAL] CWE-119 CVE-2017-17031: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17027CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17027 [CRITICAL] CWE-119 CVE-2017-17027: A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-10700CRITICALCVSS 9.8v4.3.3.02292017-09-19
CVE-2017-10700 [CRITICAL] CWE-20 CVE-2017-10700: In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execu In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
nvd