Qnap Quts Hero vulnerabilities
234 known vulnerabilities affecting qnap/quts_hero.
Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3
Vulnerabilities
Page 5 of 12
CVE-2024-50400P3HIGHCVSS 7.2vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-50400 [HIGH] CWE-134 CVE-2024-50400: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50401P3HIGHCVSS 7.2vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-50401 [HIGH] CWE-134 CVE-2024-50401: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50402P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+22 more2024-12-06
CVE-2024-50402 [HIGH] CWE-134 CVE-2024-50402: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build
nvd
CVE-2024-50403P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+22 more2024-12-06
CVE-2024-50403 [HIGH] CWE-134 CVE-2024-50403: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.2.2950 build
nvd
CVE-2024-48867P3HIGHCVSS 7.5vh5.1.0.2409vh5.1.0.2424+22 more2024-12-06
CVE-2024-48867 [HIGH] CWE-93 CVE-2024-48867: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to a
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2
nvd
CVE-2024-48868P3HIGHCVSS 7.5vh5.1.0.2409vh5.1.0.2424+22 more2024-12-06
CVE-2024-48868 [HIGH] CWE-93 CVE-2024-48868: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to a
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2
nvd
CVE-2023-32975P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+10 more2023-12-08
CVE-2023-32975 [HIGH] CWE-120 CVE-2023-32975: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2514 build 20230906 and later
QTS 5.1.2.2533
nvd
CVE-2023-32968P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+10 more2023-12-08
CVE-2023-32968 [HIGH] CWE-120 CVE-2023-32968: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2514 build 20230906 and later
QTS 5.1.2.2533
nvd
CVE-2023-45043P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45043 [HIGH] CWE-120 CVE-2023-45043: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-45041P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45041 [HIGH] CWE-120 CVE-2023-45041: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-45042P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45042 [HIGH] CWE-120 CVE-2023-45042: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-45044P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45044 [HIGH] CWE-120 CVE-2023-45044: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-45040P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45040 [HIGH] CWE-120 CVE-2023-45040: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-45039P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+5 more2024-01-05
CVE-2023-45039 [HIGH] CWE-120 CVE-2023-45039: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.
nvd
CVE-2023-32973P3HIGHCVSS 7.2≥ h4.5.0, < h4.5.4.2476≥ h5.0.0, < h5.0.1.2515+1 more2023-10-13
CVE-2023-32973 [HIGH] CWE-120 CVE-2023-32973: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444
nvd
CVE-2023-32971P3HIGHCVSS 7.2≥ h4.5.0, < h4.5.4.2476≥ h5.0.0, < h5.0.1.2515+1 more2023-10-06
CVE-2023-32971 [HIGH] CWE-120 CVE-2023-32971: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444
nvd
CVE-2023-32972P3HIGHCVSS 7.2≥ h4.5.0, < h4.5.4.2476≥ h5.0.0, < h5.0.1.2515+1 more2023-10-06
CVE-2023-32972 [HIGH] CWE-120 CVE-2023-32972: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444
nvd
CVE-2024-53699P3HIGHCVSS 7.2vh5.2.0.2737vh5.2.0.2782+8 more2025-03-07
CVE-2024-53699 [HIGH] CWE-787 CVE-2024-53699: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.3.3006 build 20250108 and later
QuTS hero h5.
nvd
CVE-2024-53697P3HIGHCVSS 7.2vh5.2.0.2737vh5.2.0.2782+8 more2025-03-07
CVE-2024-53697 [HIGH] CWE-787 CVE-2024-53697: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.3.3006 build 20250108 and later
QuTS hero h5.
nvd
CVE-2024-38638P3HIGHCVSS 7.2vh5.1.0.2409vh5.1.0.2424+13 more2025-03-07
CVE-2024-38638 [HIGH] CWE-787 CVE-2024-38638: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.
QTS 5.2.x/QuTS hero h5.2.x are not affected.
We have already fixed the vulnerability in the following versions:
QTS 5.1
nvd