Qnap

Qts

237 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.24%
  • Veröffentlicht 21.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • EPSS 3.24%
  • Veröffentlicht 21.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • EPSS 3.24%
  • Veröffentlicht 21.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • EPSS 1.89%
  • Veröffentlicht 21.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • EPSS 1.23%
  • Veröffentlicht 19.09.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.

  • EPSS 51.07%
  • Veröffentlicht 14.09.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on ...

  • EPSS 0.28%
  • Veröffentlicht 15.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.

  • EPSS 11.85%
  • Veröffentlicht 15.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.

  • EPSS 17.98%
  • Veröffentlicht 23.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.

  • EPSS 78.13%
  • Veröffentlicht 23.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.