Qnap Systems Inc Quts Hero vulnerabilities

217 known vulnerabilities affecting qnap_systems_inc/quts_hero.

Total CVEs
217
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL11HIGH80MEDIUM90LOW36

Vulnerabilities

Page 10 of 11
CVE-2023-32973HIGHCVSS 7.2≥ h5.0.x, < h5.0.1.2515 build 20230907≥ h5.1.x, < h5.1.0.2424 build 20230609+1 more2023-10-13
CVE-2023-32973 [HIGH] CWE-120 CVE-2023-32973: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444
cvelistv5nvd
CVE-2023-34975HIGHCVSS 8.8≥ h4.5.x, < h4.5.4.2626 build 202312252023-10-13
CVE-2023-34975 [HIGH] CWE-78 CVE-2023-34975: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and late
cvelistv5nvd
CVE-2023-32970MEDIUMCVSS 4.9≥ h5.0.x, < h5.0.1.2515 build 20230907≥ h5.1.x, < h5.1.0.2453 build 20230708+1 more2023-10-13
CVE-2023-32970 [MEDIUM] CWE-476 CVE-2023-32970: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h5.0.1.2515
cvelistv5nvd
CVE-2023-32971HIGHCVSS 7.2≥ h5.0.x, < h5.0.1.2515 build 20230907≥ h5.1.x, < h5.1.0.2424 build 20230609+1 more2023-10-06
CVE-2023-32971 [HIGH] CWE-120 CVE-2023-32971: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444
cvelistv5nvd
CVE-2023-32972HIGHCVSS 7.2≥ h5.0.x, < h5.0.1.2515 build 20230907≥ h5.1.x, < h5.1.0.2424 build 20230609+1 more2023-10-06
CVE-2023-32972 [HIGH] CWE-120 CVE-2023-32972: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444
cvelistv5nvd
CVE-2023-23362HIGHCVSS 8.8≥ h5.0.*, < h5.0.1.2376 build 20230421≥ h4.5.*, < h4.5.4.2374 build 202304172023-09-22
CVE-2023-23362 [HIGH] CWE-78 CVE-2023-23362: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later
cvelistv5nvd
CVE-2023-34971HIGHCVSS 8.8≥ h5.1.*, < h5.1.0.2424 build 20230609≥ h4.5.*, < h4.5.4.2476 build 202307282023-08-24
CVE-2023-34971 [HIGH] CWE-326 CVE-2023-34971: An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5
cvelistv5nvd
CVE-2023-34972MEDIUMCVSS 6.5≥ h5.1.*, < h5.1.0.2424 build 202306092023-08-24
CVE-2023-34972 [MEDIUM] CWE-319 CVE-2023-34972: A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP ope A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 2
cvelistv5nvd
CVE-2023-34973MEDIUMCVSS 5.3≥ h5.1.*, < h5.1.0.2424 build 202306092023-08-24
CVE-2023-34973 [MEDIUM] CWE-331 CVE-2023-34973: An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploit An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero
cvelistv5nvd
CVE-2023-23355HIGHCVSS 7.2≥ h5.0.*, < h5.0.1.2348 build 20230324≥ h4.5.*, < h4.5.4.2374 build 202304172023-03-29
CVE-2023-23355 [HIGH] CWE-77 CVE-2023-23355: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors. QES is not affected. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QTS 4.
cvelistv5nvd
CVE-2022-27597LOWCVSS 2.7≥ unspecified, < h5.0.1.2348 build 202303242023-03-29
CVE-2022-27597 [LOW] CWE-125 CVE-2022-27597: A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the followin
cvelistv5nvd
CVE-2022-27598LOWCVSS 2.7≥ unspecified, < h5.0.1.2348 build 202303242023-03-29
CVE-2022-27598 [LOW] CWE-125 CVE-2022-27598: A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the followin
cvelistv5nvd
CVE-2022-27596CRITICALCVSS 9.8≥ h5.0.1, < h5.0.1.2248 build 202212152023-01-30
CVE-2022-27596 [CRITICAL] CWE-89 CVE-2022-27596: A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this v A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
cvelistv5nvd
CVE-2021-44051HIGHCVSS 8.8≥ unspecified, < h5.0.0.1986 build 202203242022-05-05
CVE-2021-44051 [HIGH] CWE-77 CVE-2021-44051: A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20
cvelistv5nvd
CVE-2021-44052HIGHCVSS 8.1≥ unspecified, < h4.5.4.1971 build 20220310≥ unspecified, < h5.0.0.1986 build 202203242022-05-05
CVE-2021-44052 [HIGH] CWE-59 CVE-2021-44052: An improper link resolution before file access ('Link Following') vulnerability has been reported to An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vul
cvelistv5nvd
CVE-2021-44054MEDIUMCVSS 6.1≥ unspecified, < h5.0.0.1949 build 20220215≥ unspecified, < h4.5.4.1951 build 202202182022-05-05
CVE-2021-44054 [MEDIUM] CWE-601 CVE-2021-44054: An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later
cvelistv5nvd
CVE-2021-44053MEDIUMCVSS 6.1≥ unspecified, < h5.0.0.1986 build 20220324≥ unspecified, < h4.5.4.1971 build 202203102022-05-05
CVE-2021-44053 [MEDIUM] CWE-79 CVE-2021-44053: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.
cvelistv5nvd
CVE-2021-38693MEDIUMCVSS 5.3≥ unspecified, < h5.0.0.1949 build 20220215≥ unspecified, < h4.5.4.1951 build 202202182022-05-05
CVE-2021-38693 [MEDIUM] CWE-22 CVE-2021-38693: A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appl
cvelistv5nvd
CVE-2021-38674MEDIUMCVSS 6.1≥ unspecified, < h4.5.4.1771 build 202108252022-01-07
CVE-2021-38674 [MEDIUM] CWE-79 CVE-2021-38674: A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build 20210825 and later QTS 4.5.4.1787 build
cvelistv5nvd
CVE-2021-34343HIGHCVSS 7.2≥ unspecified, < h4.5.4.1771 build 202108252021-09-10
CVE-2021-34343 [HIGH] CWE-787 CVE-2021-34343: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
cvelistv5nvd