9.8

CVE-2020-2509

Warnung

Command Injection Vulnerability in QTS and QuTS hero

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version < 4.2.6
Qnap ≫ Qts Version >= 4.3.5 < 4.3.6
Qnap ≫ Qts Version >= 4.4.0 < 4.5.1
Qnap ≫ Qts Version 4.2.6 Update -
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107
Qnap ≫ Qts Version 4.2.6 Update build_20200109
Qnap ≫ Qts Version 4.2.6 Update build_20200421
Qnap ≫ Qts Version 4.2.6 Update build_20200611
Qnap ≫ Qts Version 4.2.6 Update build_20200821
Qnap ≫ Qts Version 4.3.3.0174
Qnap ≫ Qts Version 4.3.3.0868
Qnap ≫ Qts Version 4.3.3.0998
Qnap ≫ Qts Version 4.3.3.1051
Qnap ≫ Qts Version 4.3.3.1098
Qnap ≫ Qts Version 4.3.3.1161
Qnap ≫ Qts Version 4.3.3.1252
Qnap ≫ Qts Version 4.3.3.1315
Qnap ≫ Qts Version 4.3.3.1386
Qnap ≫ Qts Version 4.3.3.1432
Qnap ≫ Qts Version 4.3.4.0358
Qnap ≫ Qts Version 4.3.4.0358 Update beta1
Qnap ≫ Qts Version 4.3.4.0370
Qnap ≫ Qts Version 4.3.4.0370 Update beta1
Qnap ≫ Qts Version 4.3.4.0372
Qnap ≫ Qts Version 4.3.4.0372 Update beta1
Qnap ≫ Qts Version 4.3.4.0374
Qnap ≫ Qts Version 4.3.4.0374 Update beta1
Qnap ≫ Qts Version 4.3.4.0387
Qnap ≫ Qts Version 4.3.4.0387 Update beta2
Qnap ≫ Qts Version 4.3.4.0411
Qnap ≫ Qts Version 4.3.4.0416
Qnap ≫ Qts Version 4.3.4.0427
Qnap ≫ Qts Version 4.3.4.0434
Qnap ≫ Qts Version 4.3.4.0435
Qnap ≫ Qts Version 4.3.4.0451
Qnap ≫ Qts Version 4.3.4.0483
Qnap ≫ Qts Version 4.3.4.0486
Qnap ≫ Qts Version 4.3.4.0506
Qnap ≫ Qts Version 4.3.4.0516
Qnap ≫ Qts Version 4.3.4.0526
Qnap ≫ Qts Version 4.3.4.0551
Qnap ≫ Qts Version 4.3.4.0557
Qnap ≫ Qts Version 4.3.4.0561
Qnap ≫ Qts Version 4.3.4.0569
Qnap ≫ Qts Version 4.3.4.0593
Qnap ≫ Qts Version 4.3.4.0597
Qnap ≫ Qts Version 4.3.4.0604
Qnap ≫ Qts Version 4.3.4.0899
Qnap ≫ Qts Version 4.3.4.1029
Qnap ≫ Qts Version 4.3.4.1082
Qnap ≫ Qts Version 4.3.4.1190
Qnap ≫ Qts Version 4.3.4.1282
Qnap ≫ Qts Version 4.3.4.1368
Qnap ≫ Qts Version 4.3.4.1417
Qnap ≫ Qts Version 4.3.4.1463
Qnap ≫ Qts Version 4.3.6 Update -
Qnap ≫ Qts Version 4.3.6.0895
Qnap ≫ Qts Version 4.3.6.0907
Qnap ≫ Qts Version 4.3.6.0923
Qnap ≫ Qts Version 4.3.6.0944
Qnap ≫ Qts Version 4.3.6.0959
Qnap ≫ Qts Version 4.3.6.0979
Qnap ≫ Qts Version 4.3.6.0993
Qnap ≫ Qts Version 4.3.6.1013
Qnap ≫ Qts Version 4.3.6.1033
Qnap ≫ Qts Version 4.3.6.1070
Qnap ≫ Qts Version 4.3.6.1154
Qnap ≫ Qts Version 4.3.6.1218
Qnap ≫ Qts Version 4.3.6.1263
Qnap ≫ Qts Version 4.3.6.1286
Qnap ≫ Qts Version 4.3.6.1333
Qnap ≫ Qts Version 4.3.6.1411
Qnap ≫ Qts Version 4.3.6.1446
Qnap ≫ Qts Version 4.5.1 Update -
Qnap ≫ Qts Version 4.5.1.1456
Qnap ≫ Qts Version 4.5.1.1461
Qnap ≫ Qts Version 4.5.1.1465
Qnap ≫ Qts Version 4.5.1.1480
Qnap ≫ Qts Version 4.5.2 Update -
Qnap ≫ Quts Hero Version < h4.5.1
Qnap ≫ Quts Hero Version h4.5.1 Update -
Qnap ≫ Quts Hero Version h4.5.1.1472

11.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

Schwachstelle

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 33.38% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-21-05
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-2509
US Government Resource