CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
21.1%
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
QuTScloud, QVR, QES are not affected.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2790 build 20240605 and later
QuTS hero h4.5.4.2626 build 20231225 and later
Vendor | Product | Version | CPE |
---|---|---|---|
qnap | qts | 4.5.4.1715 | cpe:2.3:o:qnap:qts:4.5.4.1715:build_20210630:*:*:*:*:*:* |
qnap | qts | 4.5.4.1723 | cpe:2.3:o:qnap:qts:4.5.4.1723:build_20210708:*:*:*:*:*:* |
qnap | qts | 4.5.4.1741 | cpe:2.3:o:qnap:qts:4.5.4.1741:build_20210726:*:*:*:*:*:* |
qnap | qts | 4.5.4.1787 | cpe:2.3:o:qnap:qts:4.5.4.1787:build_20210910:*:*:*:*:*:* |
qnap | qts | 4.5.4.1800 | cpe:2.3:o:qnap:qts:4.5.4.1800:build_20210923:*:*:*:*:*:* |
qnap | qts | 4.5.4.1892 | cpe:2.3:o:qnap:qts:4.5.4.1892:build_20211223:*:*:*:*:*:* |
qnap | qts | 4.5.4.1931 | cpe:2.3:o:qnap:qts:4.5.4.1931:build_20220128:*:*:*:*:*:* |
qnap | qts | 4.5.4.2012 | cpe:2.3:o:qnap:qts:4.5.4.2012:build_20220419:*:*:*:*:*:* |
qnap | qts | 4.5.4.2117 | cpe:2.3:o:qnap:qts:4.5.4.2117:build_20220802:*:*:*:*:*:* |
qnap | qts | 4.5.4.2280 | cpe:2.3:o:qnap:qts:4.5.4.2280:build_20230112:*:*:*:*:*:* |
[
{
"defaultStatus": "unaffected",
"product": "QTS",
"vendor": "QNAP Systems Inc.",
"versions": [
{
"lessThan": "4.5.4.2790 build 20240605",
"status": "affected",
"version": "4.5.x",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QuTS hero",
"vendor": "QNAP Systems Inc.",
"versions": [
{
"lessThan": "h4.5.4.2626 build 20231225",
"status": "affected",
"version": "h4.5.x",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QuTScloud",
"vendor": "QNAP Systems Inc.",
"versions": [
{
"status": "unaffected",
"version": "c5.x.x"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QVR",
"vendor": "QNAP Systems Inc.",
"versions": [
{
"status": "unaffected",
"version": "5.1.0"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QES",
"vendor": "QNAP Systems Inc.",
"versions": [
{
"status": "unaffected",
"version": "2.2.0"
}
]
}
]