Vulnerabilidades em QNAP Systems Inc.

556 resultados
Análise Vexday

Com 556 CVEs catalogadas e 8 confirmadas em exploração ativa pelo CISA KEV, os dispositivos QNAP apresentam uma taxa de exploração real 3,2 vezes acima da média geral do catálogo — sinal de que vulnerabilidades nessa plataforma despertam interesse consistente de agentes maliciosos. A CVE mais perigosa em atividade, CVE-2022-27593, registra EPSS de 0,8791, indicando altíssima probabilidade de exploração, e está inserida num conjunto de 39 vulnerabilidades críticas que exige atenção prioritária de equipes de correção. O tipo de falha mais recorrente, CWE-476 (desreferenciamento de ponteiro nulo), pode indicar problemas estruturais na qualidade do código que alimentam esse volume. O surgimento de 24 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos frequentes de patching para quem mantém appliances QNAP expostos à rede.

CVE-2024-21900MEDIUMQTS, QuTS hero, QuTScloudEPSS 9.4%CVE-2021-28797CRITICALStack Buffer Overflow in Surveillance StationEPSS 5.9%CVE-2020-2507CRITICALcommand injection vulnerability in HelpdeskEPSS 3.0%CVE-2020-2501Stack Buffer Overflow in Surveillance StationEPSS 2.9%CVE-2019-7198Command Injection Vulnerability in QTS and QuTS heroEPSS 2.7%CVE-2022-27596CRITICALVulnerability in QTSEPSS 2.7%CVE-2020-25847HIGHCommand Injection Vulnerability in QTS and QuTS heroEPSS 2.5%CVE-2024-32766CRITICALQTS, QuTS hero, QuTScloudEPSS 2.3%CVE-2024-50388CRITICALHBS 3 Hybrid Backup SyncEPSS 2.3%CVE-2020-2490HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 2.2%CVE-2018-19950If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SystEPSS 2.1%CVE-2020-2506HIGHimproper access control vulnerability in HelpdeskEPSS 2.0%KEVCVE-2021-34343MEDIUMBuffer Overflow Vulnerability in QTS, QuTS hero, and QuTScloudEPSS 1.9%CVE-2020-2508HIGHCommand Injection Vulnerability in QTS and QuTS heroEPSS 1.8%CVE-2021-28804Command Injection Vulnerabilities in QTS and QuTS heroEPSS 1.8%CVE-2021-28802Command Injection Vulnerabilities in QTS and QuTS heroEPSS 1.8%CVE-2020-36195CRITICALSQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-OnEPSS 1.8%CVE-2023-39295HIGHQuMagieEPSS 1.7%CVE-2021-28815MEDIUMInsecure Storage of Sensitive Information in myQNAPcloud LinkEPSS 1.7%CVE-2020-2492HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 1.7%