Known vulnerabilities in QNAP QTS 5.0.0.1850 build 20211111 - page 2

Software: QNAP QTS
Version: 5.0.0.1850 build 20211111
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 39
Public exploits: 6
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 5.0.0.1850 build 20211111 QNAP QTS 5.0.0.1850 build 20211111 is affected by 39 vulnerabilities: 1 critical, 11 high, 21 medium, 6 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64080 - Out-of-bounds read
CVE-2022-28330
CWE-125 Medium
No
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022070730
and 11 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Public exploit available
No
4.5.4.2125 20220810, 5.0.0.2131 20220815 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU61622 - Out-of-bounds read
CVE-2022-23124
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61621 - Out-of-bounds read
CVE-2022-23123
CWE-125 Medium
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61620 - Improper Handling of Exceptional Conditions
CVE-2022-23121
CWE-755 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 7 more
#VU61619 - Stack-based buffer overflow
CVE-2022-23125
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 6 more
#VU61618 - Stack-based buffer overflow
CVE-2022-23122
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU61617 - Stack-based buffer overflow
CVE-2022-0194
CWE-121 High
No
No
4.5.4.2012 20220419 25.03.2022 SB2022032507
SB2022042577
SB2022042578
and 5 more
#VU59601 - Improper Control of Generation of Code ('Code Injection')
CWE-94 Critical
No
Exploited
4.5.4.1892 20211223, 5.0.0.1891 20211221 14.01.2022 SB2022011403
#VU58098 - Improper Access Control
CVE-2016-2124
CWE-284 High
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 34 more
#VU58097 - Permissions, Privileges, and Access Controls
CVE-2020-25717
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021112913
and 43 more
#VU58096 - Permissions, Privileges, and Access Controls
CVE-2020-25718
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU58095 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-25719
CWE-362 Low
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021121644
and 17 more
#VU58094 - Improper Authentication
CVE-2020-25721
CWE-287 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 13 more
#VU58093 - Permissions, Privileges, and Access Controls
CVE-2020-25722
CWE-264 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021113012
and 14 more
#VU58092 - Use After Free
CVE-2021-3738
CWE-416 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2022012012
and 11 more
#VU58091 - Improper input validation
CVE-2021-23192
CWE-20 Medium
No
No
5.0.0.1891 20211221 10.11.2021 SB2021111008
SB2021111201
SB2021112914
and 19 more
#VU52802 - Heap-based Buffer Overflow
CVE-2021-31439
CWE-122 Medium
No
No
4.5.4.2012 20220419 03.05.2021 SB2021050308
SB2022042577
SB2022042578
and 6 more
#VU22304 - Memory corruption
CVE-2019-11043
CWE-119 High
Public exploit available
Exploited
5.0.1.2034 20220515 27.10.2019 SB2019102707
SB2019102708
SB2019102709
and 22 more


Showing elements 21 - 40 out of 39