Vulnerabilities in QNAP Systems Inc.

556 results
Vexday analysis

Com 556 CVEs catalogadas e 8 confirmadas em exploração ativa pelo CISA KEV, os dispositivos QNAP apresentam uma taxa de exploração real 3,2 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nessa plataforma despertam interesse consistente de agentes maliciosos. A CVE mais perigosa em atividade, CVE-2022-27593, registra EPSS de 0,8791, indicando altíssima probabilidade de exploração, e está inserida num conjunto de 39 vulnerabilidades críticas que exige atenção prioritária de equipes de correção. O tipo de falha mais recorrente, CWE-476 (desreferenciamento de ponteiro nulo), pode indicar problemas estruturais na qualidade do código que alimentam esse volume. O surgimento de 24 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos frequentes de patching para quem mantém appliances QNAP expostos à rede.

CVE-2023-47218MEDIUMQTS, QuTS hero, QuTScloudEPSS 89.9%CVE-2022-27593CRITICALDeadBolt RansomwareEPSS 87.9%KEVCVE-2021-28799CRITICALImproper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)EPSS 78.3%KEVCVE-2023-47565HIGHLegacy VioStor NVREPSS 73.3%KEVCVE-2023-51364HIGHQTS, QuTS hero, QuTScloudEPSS 41.6%CVE-2024-27130HIGHQTS, QuTS heroEPSS 38.1%CVE-2023-51365HIGHQTS, QuTS hero, QuTScloudEPSS 34.8%CVE-2020-2509CRITICALCommand Injection Vulnerability in QTS and QuTS heroEPSS 33.4%KEVCVE-2018-19949CRITICALIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue EPSS 24.4%KEVCVE-2024-21899CRITICALQTS, QuTS hero, QuTScloudEPSS 24.4%CVE-2018-19953MEDIUMIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issuEPSS 23.9%KEVCVE-2024-53691HIGHQTS, QuTS heroEPSS 20.1%CVE-2023-23368CRITICALQTS, QuTS hero, QuTScloudEPSS 18.8%CVE-2024-21901MEDIUMmyQNAPcloudEPSS 18.7%CVE-2020-36197HIGHImproper Access Control Vulnerability in Music StationEPSS 18.5%CVE-2018-19943HIGHIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these isEPSS 17.7%KEVCVE-2021-28809CRITICALMissing Authentication for Critical Function in RTRR Server in HBS3EPSS 15.8%CVE-2023-23369CRITICALQTS, Multimedia Console, and Media Streaming add-onEPSS 14.5%CVE-2023-50358MEDIUMQTS, QuTS hero, QuTScloudEPSS 13.5%CVE-2024-50387CRITICALSMB ServiceEPSS 10.1%