9.8

CVE-2020-36195

SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version < 4.3.3
Qnap ≫ Qts Version >= 4.3.4 < 4.3.6
Qnap ≫ Qts Version 4.3.3
Qnap ≫ Qts Version 4.3.3.0095
Qnap ≫ Qts Version 4.3.3.0096
Qnap ≫ Qts Version 4.3.3.0136
Qnap ≫ Qts Version 4.3.3.0154
Qnap ≫ Qts Version 4.3.3.0174
Qnap ≫ Qts Version 4.3.3.0188
Qnap ≫ Qts Version 4.3.3.0210
Qnap ≫ Qts Version 4.3.3.0229
Qnap ≫ Qts Version 4.3.3.0238
Qnap ≫ Qts Version 4.3.3.0262
Qnap ≫ Qts Version 4.3.3.0299
Qnap ≫ Qts Version 4.3.3.0351
Qnap ≫ Qts Version 4.3.3.0353
Qnap ≫ Qts Version 4.3.3.0361
Qnap ≫ Qts Version 4.3.3.0369
Qnap ≫ Qts Version 4.3.3.0378
Qnap ≫ Qts Version 4.3.3.0396
Qnap ≫ Qts Version 4.3.3.0404
Qnap ≫ Qts Version 4.3.3.0416
Qnap ≫ Qts Version 4.3.3.0418
Qnap ≫ Qts Version 4.3.3.0448
Qnap ≫ Qts Version 4.3.3.0514
Qnap ≫ Qts Version 4.3.3.0546
Qnap ≫ Qts Version 4.3.3.0570
Qnap ≫ Qts Version 4.3.3.0868
Qnap ≫ Qts Version 4.3.3.0998
Qnap ≫ Qts Version 4.3.3.1051
Qnap ≫ Qts Version 4.3.3.1098
Qnap ≫ Qts Version 4.3.3.1161
Qnap ≫ Qts Version 4.3.3.1252
Qnap ≫ Qts Version 4.3.3.1315
Qnap ≫ Qts Version 4.3.3.1386
Qnap ≫ Qts Version 4.3.3.1432
Qnap ≫ Qts Version 4.3.6 Update -
Qnap ≫ Qts Version 4.3.6.0895
Qnap ≫ Qts Version 4.3.6.0907
Qnap ≫ Qts Version 4.3.6.0923
Qnap ≫ Qts Version 4.3.6.0944
Qnap ≫ Qts Version 4.3.6.0959
Qnap ≫ Qts Version 4.3.6.0979
Qnap ≫ Qts Version 4.3.6.0993
Qnap ≫ Qts Version 4.3.6.1013
Qnap ≫ Qts Version 4.3.6.1033
Qnap ≫ Qts Version 4.3.6.1070
Qnap ≫ Qts Version 4.3.6.1154
Qnap ≫ Qts Version 4.3.6.1218
Qnap ≫ Qts Version 4.3.6.1263
Qnap ≫ Qts Version 4.3.6.1286
Qnap ≫ Qts Version 4.3.6.1333
Qnap ≫ Qts Version 4.3.6.1411
Qnap ≫ Qts Version 4.3.6.1446
Qnap ≫ Media Streaming Add-on Version < 430.1.8.10
   Qnap ≫ Qts Version 4.3.3
Qnap ≫ Media Streaming Add-on Version < 430.1.8.8
   Qnap ≫ Qts Version 4.3.6
Qnap ≫ Multimedia Console Version < 1.3.4
   Qnap ≫ Qts Version >= 4.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.752
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security@qnapsecurity.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

CWE-943 Improper Neutralization of Special Elements in Data Query Logic

The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

https://www.qnap.com/en/security-advisory/qsa-21-11
Vendor Advisory