cbcvebase.

Qnap Systems Inc Quts Hero vulnerabilities

228 known vulnerabilities affecting qnap_systems_inc/quts_hero.

Total CVEs
228
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM103LOW3

Vulnerabilities

Page 2 of 12
CVE-2019-7198P2CRITICALCVSS 9.8fixed in h4.5.1.14722020-12-10
CVE-2019-7198 [CRITICAL] CWE-77 CVE-2019-7198: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later
nvd
CVE-2023-34974P2HIGHCVSS 8.8≥ h4.5.x, < h4.5.4.2626 build 202312252024-09-06
CVE-2023-34974 [HIGH] CWE-78 CVE-2023-34974: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. QuTScloud, QVR, QES are not affected. We have already fixed the vulnerability in the following versions: QTS 4.5.4.2790 build 20240605 and later QuTS hero h4.5.4.
nvd
CVE-2022-27596P2CRITICALCVSS 9.8≥ h5.0.1, < h5.0.1.2248 build 202212152023-01-30
CVE-2022-27596 [CRITICAL] CWE-89 CVE-2022-27596: A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this v A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
nvd
CVE-2023-39303P2CRITICALCVSS 9.8≥ h5.1.x, < h5.1.3.2578 build 202311102024-02-02
CVE-2023-39303 [CRITICAL] CWE-287 CVE-2023-39303: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 buil
nvd
CVE-2021-44051P2HIGHCVSS 8.8≥ unspecified, < h5.0.0.1986 build 202203242022-05-05
CVE-2021-44051 [HIGH] CWE-77 CVE-2021-44051: A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20
nvd
CVE-2024-48859P2CRITICALCVSS 9.1≥ h5.1.x, < h5.1.9.2954 build 20241120≥ h5.2.x, < h5.2.2.2952 build 202411162024-12-06
CVE-2024-48859 [CRITICAL] CWE-287 CVE-2024-48859: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114
nvd
CVE-2024-21898P2HIGHCVSS 8.8≥ h5.1.x, < h5.1.6.2734 build 202404142024-09-06
CVE-2024-21898 [HIGH] CWE-78 CVE-2024-21898: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and l
nvd
CVE-2023-39297P2HIGHCVSS 8.8≥ h5.1.x, < h5.1.4.2596 build 20231128≥ h4.5.x, < h4.5.4.2626 build 202312252024-02-02
CVE-2023-39297 [HIGH] CWE-78 CVE-2023-39297: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later Q
nvd
CVE-2020-25847P2HIGHCVSS 8.8≥ unspecified, < h4.5.1.14912020-12-29
CVE-2020-25847 [HIGH] CWE-77 CVE-2020-25847: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
nvd
CVE-2023-23362P2HIGHCVSS 8.8≥ h5.0.*, < h5.0.1.2376 build 20230421≥ h4.5.*, < h4.5.4.2374 build 202304172023-09-22
CVE-2023-23362 [HIGH] CWE-78 CVE-2023-23362: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later
nvd
CVE-2023-34975P2HIGHCVSS 8.8≥ h4.5.x, < h4.5.4.2626 build 202312252023-10-13
CVE-2023-34975 [HIGH] CWE-78 CVE-2023-34975: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and late
nvd
CVE-2023-50364P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.6.2734 build 202404142024-04-26
CVE-2023-50364 [HIGH] CWE-120 CVE-2023-50364: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2023-50361P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.6.2734 build 202404142024-04-26
CVE-2023-50361 [HIGH] CWE-120 CVE-2023-50361: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2023-50362P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.6.2734 build 202404142024-04-26
CVE-2023-50362 [HIGH] CWE-120 CVE-2023-50362: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2024-32763P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.8.2823 build 202407122024-09-06
CVE-2024-32763 [HIGH] CWE-120 CVE-2024-32763: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 bu
nvd
CVE-2024-27127P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.7.2770 build 202405202024-05-21
CVE-2024-27127 [HIGH] CWE-415 CVE-2024-27127: A double free vulnerability has been reported to affect several QNAP operating system versions. If e A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and late
nvd
CVE-2024-27129P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.7.2770 build 202405202024-05-21
CVE-2024-27129 [HIGH] CWE-120 CVE-2024-27129: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 bui
nvd
CVE-2024-27128P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.7.2770 build 202405202024-05-21
CVE-2024-27128 [HIGH] CWE-120 CVE-2024-27128: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 bui
nvd
CVE-2024-50397P3HIGHCVSS 8.8≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-50397 [HIGH] CWE-134 CVE-2024-50397: A use of externally-controlled format string vulnerability has been reported to affect several QNAP A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025
nvd
CVE-2023-47568P3HIGHCVSS 8.8≥ h5.1.x, < h5.1.5.2647 build 20240118≥ h4.5.x, < h4.5.4.2626 build 202312252024-02-02
CVE-2023-47568 [HIGH] CWE-89 CVE-2023-47568: A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QuTS
nvd
Qnap Systems Inc Quts Hero vulnerabilities | cvebase