8.8

CVE-2021-44051

Command injection

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 5.0.0.1986 build 20220324 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version >= 5.0.0.1716 < 5.0.0.1986
Qnap ≫ Qts Version >= 4.3.3.0174 < 4.3.3.1945
Qnap ≫ Qts Version >= 4.3.4.0899 < 4.3.4.1976
Qnap ≫ Qts Version >= 4.3.6.0895 < 4.3.6.1965
Qnap ≫ Qts Version >= 4.4.0.0883 < 4.5.4.1991
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107
Qnap ≫ Qts Version 4.2.6 Update build_20200109
Qnap ≫ Qts Version 4.2.6 Update build_20200421
Qnap ≫ Qts Version 4.2.6 Update build_20200611
Qnap ≫ Qts Version 4.2.6 Update build_20200821
Qnap ≫ Qts Version 4.2.6 Update build_20210327
Qnap ≫ Qts Version 4.2.6 Update build_20211215
Qnap ≫ Quts Hero Version < h4.5.4.1771
Qnap ≫ Quts Hero Version >= h5.0.0.1772 < h5.0.0.1986
Qnap ≫ Qutscloud Version < c5.0.1.1998
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.64% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
security@qnapsecurity.com.tw 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-22-16
Vendor Advisory