Known vulnerabilities in QNAP QTS 4.3.4.0899 build 20190322 - page 2

Software: QNAP QTS
Version: 4.3.4.0899 build 20190322
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 41
Public exploits: 9
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 4.3.4.0899 build 20190322 QNAP QTS 4.3.4.0899 build 20190322 is affected by 41 vulnerabilities: 14 high, 21 medium, 6 low Critical High Medium Low

Vulnerabilities (41)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61622 - Out-of-bounds read
CVE-2022-23124
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61621 - Out-of-bounds read
CVE-2022-23123
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61619 - Stack-based buffer overflow
CVE-2022-23125
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61618 - Stack-based buffer overflow
CVE-2022-23122
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61617 - Stack-based buffer overflow
CVE-2022-0194
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU56436 - Stack-based buffer overflow
CVE-2021-34343
CWE-121 High
No
No
4.3.3.1693 20210624, 4.3.6.1750 20210730, 5.0.0.1716 20210701 09.09.2021 SB2021090917
#VU56435 - Stack-based buffer overflow
CVE-2021-28816
CWE-121 High
No
No
4.3.3.1693 20210624, 4.3.6.1750 20210730, 5.0.0.1716 20210701 09.09.2021 SB2021090917
#VU29486 - Improper input validation
CVE-2020-14303
CWE-20 Medium
No
No
4.3.6.1411 20200825 02.07.2020 SB2020070224
SB2020071805
SB2020072104
and 9 more
#VU29484 - Resource exhaustion
CVE-2020-10745
CWE-400 Medium
No
No
4.3.3.1386 20200821, 4.3.6.1411 20200825 02.07.2020 SB2020070224
SB2020071805
SB2020072104
and 8 more
#VU28116 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2019-7194
CWE-610 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28115 - Improper input validation
CVE-2019-7193
CWE-20 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU28114 - Improper Access Control
CVE-2019-7192
CWE-284 High
Public exploit available
Exploited
4.3.6.1070 20190919, 4.4.1.1064 20190918 20.05.2020 SB2019122502
#VU26104 - NULL Pointer Dereference
CVE-2019-19269
CWE-476 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 17.03.2020 SB2020022519
SB2020031705
SB2020083115
and 5 more
#VU25596 - Out-of-bounds read
CVE-2020-9272
CWE-125 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 25.02.2020 SB2020022519
SB2020030101
SB2020031705
and 2 more
#VU25595 - Use After Free
CVE-2020-9273
CWE-416 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 25.02.2020 SB2020022519
SB2020022707
SB2020030101
and 8 more
#VU30580 - Improper Certificate Validation
CVE-2019-19271
CWE-295 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU30581 - NULL Pointer Dereference
CVE-2019-19272
CWE-476 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2019112628
SB2020083115
SB2019112925
#VU35035 - Improper Certificate Validation
CVE-2019-19270
CWE-295 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 26.11.2019 SB2016040501
SB2020083115
SB2020011349
and 3 more
#VU22564 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-18217
CWE-835 Medium
No
No
4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817 06.11.2019 SB2019110639
SB2019110640
SB2020021217
and 8 more
#VU20007 - Permissions, Privileges, and Access Controls
CVE-2017-7418
CWE-264 Low
No
No
4.2.6 20200821, 4.3.3.1315 20200611, 4.3.6.1411 20200825, 4.4.3.1400 20200817 08.08.2019 SB2019080821
SB2017042201
SB2019081425
and 7 more


Showing elements 21 - 40 out of 41