Qnap Video Station vulnerabilities

15 known vulnerabilities affecting qnap/video_station.

Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM3LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-14024LOWCVSS 0.1≥ 5.0.0, < 5.8.22026-03-11
CVE-2024-14024 [LOW] CWE-295 CVE-2024-14024: An improper certificate validation vulnerability has been reported to affect Video Station. If an at An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and
nvd
CVE-2024-14025LOWCVSS 0.1≥ 5.0.0, < 5.8.22026-03-11
CVE-2024-14025 [LOW] CWE-89 CVE-2024-14025: An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
nvd
CVE-2024-56804MEDIUMCVSS 5.3≥ 5.8.0, < 5.8.42025-10-03
CVE-2024-56804 [MEDIUM] CWE-89 CVE-2024-56804: An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.4 and later
nvd
CVE-2023-47563HIGHCVSS 8.8≥ 5.0.0, < 5.8.22024-09-06
CVE-2023-47563 [HIGH] CWE-77 CVE-2023-47563: An OS command injection vulnerability has been reported to affect Video Station. If exploited, the v An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
nvd
CVE-2023-50360HIGHCVSS 8.8≥ 5.0.0, < 5.8.22024-09-06
CVE-2023-50360 [HIGH] CWE-89 CVE-2023-50360: A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerabi A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 ) and later
nvd
CVE-2023-41287HIGHCVSS 8.8≥ 5.7.0, < 5.7.22024-01-05
CVE-2023-41287 [MEDIUM] CWE-89 CVE-2023-41287: A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerabi A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
nvd
CVE-2023-41288HIGHCVSS 8.8≥ 5.7.0, < 5.7.22024-01-05
CVE-2023-41288 [HIGH] CWE-78 CVE-2023-41288: An OS command injection vulnerability has been reported to affect Video Station. If exploited, the v An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
nvd
CVE-2023-34976HIGHCVSS 8.8fixed in 5.7.02023-10-13
CVE-2023-34976 [CRITICAL] CWE-89 CVE-2023-34976: A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerabi A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later
nvd
CVE-2023-34975HIGHCVSS 8.8fixed in 5.7.02023-10-13
CVE-2023-34975 [MEDIUM] CWE-78 CVE-2023-34975: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and la
nvd
CVE-2023-34977MEDIUMCVSS 5.4fixed in 2023.07.272023-10-13
CVE-2023-34977 [MEDIUM] CWE-79 CVE-2023-34977: A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later
nvd
CVE-2021-44055CRITICALCVSS 9.8fixed in 5.1.8≥ 5.2.0, < 5.3.13+1 more2022-05-05
CVE-2021-44055 [MEDIUM] CWE-862 CVE-2021-44055: An missing authorization vulnerability has been reported to affect QNAP device running Video Station An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02
nvd
CVE-2021-44056CRITICALCVSS 9.8fixed in 5.1.8≥ 5.2.0, < 5.3.13+1 more2022-05-05
CVE-2021-44056 [HIGH] CWE-287 CVE-2021-44056: An improper authentication vulnerability has been reported to affect QNAP device running Video Stati An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Stati
nvd
CVE-2021-28812HIGHCVSS 8.8fixed in 5.5.42021-06-03
CVE-2021-28812 [HIGH] CWE-77 CVE-2021-28812: A command injection vulnerability has been reported to affect certain versions of Video Station. If A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTSclou
nvd
CVE-2019-7184MEDIUMCVSS 4.8fixed in 5.4.3fixed in 5.3.102019-12-05
CVE-2019-7184 [MEDIUM] CWE-79 CVE-2019-7184: This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
nvd
CVE-2017-13071CRITICALCVSS 9.8v5.1.3v5.2.0+1 more2017-11-22
CVE-2017-13071 [CRITICAL] CWE-77 CVE-2017-13071: QNAP has already patched this vulnerability. This security concern allows a remote attacker to run a QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
cvelistv5nvd