QNAP Vulnerabilities and Affected Products
Vulnerabilities associated with media_streaming_add-on.
Products
Clear product- qts38 vulnerabilities
- quts_hero27 vulnerabilities
- Photo Station8 vulnerabilities
- qutscloud8 vulnerabilities
- Q'center Virtual Appliance7 vulnerabilities
- QNAP Network-Attached Storage (NAS)5 vulnerabilities
- Network Attached Storage (NAS)4 vulnerabilities
- notes_station_34 vulnerabilities
- QNAP Media Streaming Add-On4 vulnerabilities
- QNAP QTS4 vulnerabilities
- media_streaming_add-on3 vulnerabilities
- qurouter3 vulnerabilities
- Helpdesk2 vulnerabilities
- malware_remover2 vulnerabilities
- music_station2 vulnerabilities
- QTS Login function2 vulnerabilities
- QTS Password function2 vulnerabilities
- qufirewall2 vulnerabilities
- ai_core1 vulnerability
- App Center in QTS1 vulnerability
- container_station1 vulnerability
- hbs_31 vulnerability
- Helpdesk in QTS1 vulnerability
- iartist_lite1 vulnerability
- LDAP Server in QTS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-50395MEDIUM | Media Streaming add-onAn authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later CWE-639Nov 22, 2024 | CVSS6.9v4.0 | EPSS1.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47220MEDIUM | Media Streaming add-onAn OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later CWE-78May 3, 2024 | CVSS6.6v3.1 | EPSS1.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47222CRITICAL | Media Streaming add-onAn exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later | CVSS9.6v3.1 | EPSS0.544% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |