Known vulnerabilities in QNAP QTS 4.2.6 build 20170905 - page 2

Software: QNAP QTS
Version: 4.2.6 build 20170905
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 45
Public exploits: 8
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 4.2.6 build 20170905 QNAP QTS 4.2.6 build 20170905 is affected by 45 vulnerabilities: 20 high, 13 medium, 12 low Critical High Medium Low

Vulnerabilities (45)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU28117 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2019-7195
CWE-610 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28116 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2019-7194
CWE-610 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28115 - Improper input validation
CVE-2019-7193
CWE-20 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28114 - Improper Access Control
CVE-2019-7192
CWE-284 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU25595 - Use After Free
CVE-2020-9273
CWE-416 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 25.02.2020 SB2020022519
SB2020022707
SB2020030101
and 8 more
#VU30580 - Improper Certificate Validation
CVE-2019-19271
CWE-295 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU30581 - NULL Pointer Dereference
CVE-2019-19272
CWE-476 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU35035 - Improper Certificate Validation
CVE-2019-19270
CWE-295 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2016040501
SB2020083115
SB2020011349
and 3 more
#VU22564 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-18217
CWE-835 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 06.11.2019 SB2019110639
SB2019110640
SB2020021217
and 8 more
#VU16770 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0713
CWE-79 Low
No
No
4.3.6.0805 20181228 02.01.2019 SB2018122806
#VU16769 - Command injection
CVE-2018-0730
CWE-77 Low
No
No
4.3.6.0805 20181228 02.01.2019 SB2018122806
#VU16039 - Buffer overflow
CVE-2018-14749
CWE-120 High
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16038 - Permissions, Privileges, and Access Controls
CVE-2018-14748
CWE-264 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16037 - Permissions, Privileges, and Access Controls
CVE-2018-14747
CWE-264 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU16036 - Command injection
CVE-2018-14746
CWE-77 Low
No
No
4.2.6 20181026, 4.3.3 20181029, 4.3.4 20181026, 4.3.5 20181110 23.11.2018 SB2018112312
#VU14321 - Command injection
CVE-2018-0714
CWE-77 Low
No
No
4.2.6 20180711, 4.3.3 20180716, 4.3.4 20180710 13.08.2018 SB2018081304
#VU13396 - Command injection
CVE-2018-0712
CWE-77 Low
No
No
4.2.6 20180504, 4.3.3 20180504, 4.3.4 20180501 20.06.2018 SB2018062004
#VU12891 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-13072
CWE-79 Low
No
No
- 21.05.2018 SB2018052115
#VU9680 - Memory corruption
CVE-2017-17033
CWE-119 High
No
No
- 18.12.2017 SB2017121505
#VU9679 - Memory corruption
CVE-2017-17032
CWE-119 High
No
No
- 18.12.2017 SB2017121505


Showing elements 21 - 40 out of 45