Known vulnerabilities in QNAP QTS 5.0.1.2145 build 20220903

Software: QNAP QTS
Version: 5.0.1.2145 build 20220903
Software CPE: cpe:2.3:a:qnap_systems:qnap_qts:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting QNAP QTS version 5.0.1.2145 build 20220903 QNAP QTS 5.0.1.2145 build 20220903 is affected by 10 vulnerabilities: 6 high, 4 medium Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130763 - Resource Management Errors
CVE-2026-43284
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508111
SB20260508120
SB20260508121
and 72 more
#VU130759 - Resource Management Errors
CVE-2026-43500
CWE-399 High
Public exploit available
Exploited
- 08.05.2026 SB20260508108
SB20260508120
SB20260508121
and 32 more
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Public exploit available
No
- 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU86371 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-50358
CWE-78 High
No
Exploited
4.2.6 20240131, 4.3.3.2644 20240131, 4.3.4.2675 20240131, 4.3.6.2665 20240131, 4.5.4.2627 20231225, 5.1.5.2645 20240116 13.02.2024 SB2024021313
#VU86370 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-47218
CWE-78 Medium
Public exploit available
No
4.2.6 20240131, 4.3.3.2644 20240131, 4.3.4.2675 20240131, 4.3.6.2665 20240131, 4.5.4.2627 20231225, 5.1.5.2645 20240116 13.02.2024 SB2024021313
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
5.0.1.2346 20230322 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71621 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-27596
CWE-89 High
No
No
5.0.1.2234 20221201 30.01.2023 SB2023013013