Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 6 of 15
CVE-2024-21905P3HIGHCVSS 8.2≥ 5.0.0, < 5.1.3.2578v5.1.3.25782024-04-26
CVE-2024-21905 [HIGH] CWE-190 CVE-2024-21905: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 b
nvd
CVE-2024-38641P3HIGHCVSS 7.8v5.1.0.2348v5.1.0.2399+11 more2024-09-06
CVE-2024-38641 [HIGH] CWE-77 CVE-2024-38641: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823 build 202
nvd
CVE-2023-23355P3HIGHCVSS 7.2fixed in 5.0.1.23462023-03-29
CVE-2023-23355 [HIGH] CWE-77 CVE-2023-23355: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors.
QES is not affected.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2346 build 20230322 and later
QTS 4.
nvd
CVE-2023-47566P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+8 more2024-02-02
CVE-2023-47566 [HIGH] CWE-78 CVE-2023-47566: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QuTS hero h5.1.5.2647 build 2024
nvd
CVE-2023-47567P3HIGHCVSS 7.2v4.5.4.1715v4.5.4.1723+20 more2024-02-02
CVE-2023-47567 [HIGH] CWE-78 CVE-2023-47567: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QTS 4.5.4.2627 build 20231225 an
nvd
CVE-2023-39302P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+6 more2024-02-02
CVE-2023-39302 [HIGH] CWE-78 CVE-2023-39302: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 2023
nvd
CVE-2023-41283P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+7 more2024-02-02
CVE-2023-41283 [HIGH] CWE-77 CVE-2023-41283: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2023-41281P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+7 more2024-02-02
CVE-2023-41281 [HIGH] CWE-77 CVE-2023-41281: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2023-41282P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+8 more2024-02-02
CVE-2023-41282 [HIGH] CWE-77 CVE-2023-41282: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2024-37041P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-37041 [HIGH] CWE-120 CVE-2024-37041: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS
nvd
CVE-2024-37044P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-37044 [HIGH] CWE-120 CVE-2024-37044: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS
nvd
CVE-2024-50398P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50398 [HIGH] CWE-134 CVE-2024-50398: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50399P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50399 [HIGH] CWE-134 CVE-2024-50399: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50400P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50400 [HIGH] CWE-134 CVE-2024-50400: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50401P3HIGHCVSS 7.2v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50401 [HIGH] CWE-134 CVE-2024-50401: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50402P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-50402 [HIGH] CWE-134 CVE-2024-50402: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build
nvd
CVE-2024-50403P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-50403 [HIGH] CWE-134 CVE-2024-50403: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.2.2950 build
nvd
CVE-2018-0721P3HIGHCVSS 7.7v4.2.6v4.3.3+1 more2018-11-27
CVE-2018-0721 [HIGH] CWE-120 CVE-2018-0721: Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
nvd
CVE-2024-48867P3HIGHCVSS 7.5v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-48867 [HIGH] CWE-93 CVE-2024-48867: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to a
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2
nvd
CVE-2024-48868P3HIGHCVSS 7.5v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-48868 [HIGH] CWE-93 CVE-2024-48868: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to a
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2
nvd