Known vulnerabilities in QNAP QTS 4.2.6 build 20200611

Software: QNAP QTS
Version: 4.2.6 build 20200611
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 25
Public exploits: 4
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 4.2.6 build 20200611 QNAP QTS 4.2.6 build 20200611 is affected by 25 vulnerabilities: 8 high, 13 medium, 4 low Critical High Medium Low

Vulnerabilities (25)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130763 - Resource Management Errors
CVE-2026-43284
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508111
SB20260508120
SB20260508121
and 72 more
#VU130759 - Resource Management Errors
CVE-2026-43500
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508108
SB20260508120
SB20260508121
and 32 more
#VU86371 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-50358
CWE-78 High
No
Exploited
4.2.6 20240131, 4.3.3.2644 20240131, 4.3.4.2675 20240131, 4.3.6.2665 20240131, 4.5.4.2627 20231225, 5.1.5.2645 20240116 13.02.2024 SB2024021313
#VU86370 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47218
CWE-78 Medium
Public exploit available
No
4.2.6 20240131, 4.3.3.2644 20240131, 4.3.4.2675 20240131, 4.3.6.2665 20240131, 4.5.4.2627 20231225, 5.1.5.2645 20240116 13.02.2024 SB2024021313
#VU65827 - Use After Free
CVE-2022-32746
CWE-416 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 30 more
#VU65826 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-32745
CWE-835 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 19 more
#VU65825 - Permissions, Privileges, and Access Controls
CVE-2022-32744
CWE-264 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 20 more
#VU65824 - Missing release of memory after effective lifetime
CVE-2022-32742
CWE-401 Low
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 36 more
#VU65820 - Permissions, Privileges, and Access Controls
CVE-2022-2031
CWE-264 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 15 more
#VU61622 - Out-of-bounds read
CVE-2022-23124
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61621 - Out-of-bounds read
CVE-2022-23123
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61620 - Improper Handling of Exceptional Conditions
CVE-2022-23121
CWE-755 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 7 more
#VU61619 - Stack-based buffer overflow
CVE-2022-23125
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61618 - Stack-based buffer overflow
CVE-2022-23122
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61617 - Stack-based buffer overflow
CVE-2022-0194
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU52802 - Heap-based Buffer Overflow
CVE-2021-31439
CWE-122 Medium
No
No
4.5.4.2012 20220419 03.05.2021 SB2021050308
SB2022042577
SB2022042578
and 6 more
#VU26104 - NULL Pointer Dereference
CVE-2019-19269
CWE-476 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 17.03.2020 SB2020022519
SB2020031705
SB2020083115
and 5 more
#VU35035 - Improper Certificate Validation
CVE-2019-19270
CWE-295 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2016040501
SB2020083115
SB2020011349
and 3 more
#VU22304 - Memory corruption
CVE-2019-11043
CWE-119 High
Public exploit available
Exploited
5.0.1.2034 20220515 27.10.2019 SB2019102707
SB2019102708
SB2019102709
and 22 more
#VU20007 - Permissions, Privileges, and Access Controls
CVE-2017-7418
CWE-264 Low
No
No
4.2.6 20200821, 4.3.3.1315 20200611, 4.3.6.1411 20200825, 4.4.3.1400 20200817 08.08.2019 SB2019080821
SB2017042201
SB2019081425
and 7 more


Showing elements 1 - 20 out of 25