Vulnerabilidades en QNAP

36 resultados
Análisis Vexday

QNAP registra 36 vulnerabilidades na base do Vexday, mas nenhuma está sob ataque ativo (KEV) ou classificada como crítica. Não há publicações recentes nos últimos 90 dias, indicando que o risco presente é histórico e não representa ameaça imediata. O panorama sugere estabilidade relativa na postura de segurança atual do fornecedor.

CVE-2018-0707Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticatedEPSS 59.2%CVE-2018-0706Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access seEPSS 48.7%CVE-2018-0708Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated userEPSS 26.3%CVE-2017-13067QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 andEPSS 16.7%CVE-2018-0710Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to ruEPSS 14.2%CVE-2018-0709Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to rEPSS 13.6%CVE-2017-17033A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2EPSS 4.4%CVE-2018-14746Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 anEPSS 3.3%CVE-2017-17028A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 EPSS 3.3%CVE-2017-17030A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) bEPSS 3.3%CVE-2017-17031A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2EPSS 3.3%CVE-2017-17032A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2EPSS 3.3%CVE-2017-17027A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) builEPSS 3.3%CVE-2017-17029A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) bEPSS 3.3%CVE-2018-0715Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code iEPSS 3.1%CVE-2018-0712Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and theiEPSS 2.6%CVE-2017-13068QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application aEPSS 2.6%CVE-2017-7640QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands aEPSS 2.3%CVE-2018-0714Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.EPSS 2.3%CVE-2017-13070A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitraEPSS 2.2%