Showing 4 vulnerabilities on this page for Network Attached Storage (NAS)

Signals CISA KEV Ransomware Nuclei
QNAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScl

CWE-285CWE-863May 13, 20211 related artifact
CVSS10.0v3.1EPSS78.3%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

QNAP NAS File Station Command Injection Vulnerability

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CWE-20CWE-77CWE-78Oct 28, 2020
CVSS9.8v3.1EPSS24.4%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

QNAP NAS File Station Cross-Site Scripting Vulnerability

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CWE-79CWE-80Oct 28, 2020
CVSS6.1v3.1EPSS23.9%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

QNAP NAS File Station Cross-Site Scripting Vulnerability

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CWE-79CWE-80Oct 28, 2020
CVSS8.0v3.1EPSS17.7%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX