Description
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5.
No analysis available yet.
Remediation
Vendor Solution
QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.1663 Build 20210504 and later QTS 4.3.3.1624 Build 20210416 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15456 | A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-21-28 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T23:01:07.180Z
Reserved: 2021-03-18T00:00:00.000Z
Link: CVE-2021-28800
No data.
Status : Modified
Published: 2021-06-24T07:15:07.580
Modified: 2024-11-21T06:00:13.670
Link: CVE-2021-28800
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD