QNAP security briefs
9 published alerts for QNAP products and services.
QNAP Photo Station Externally Controlled Reference Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-27593). Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. CISA remediation due date: 2022-09-29. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Path Traversal Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7195). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Path Traversal Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7194). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP QTS Improper Input Validation Vulnerability
QNAP QTS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7193). QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP Photo Station Improper Access Control Vulnerability
QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7192). QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19953). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Command Injection Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19949). A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS File Station Cross-Site Scripting Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19943). A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. CISA remediation due date: 2022-06-14. If you need help checking exposure, call (864) 335-9223.
QNAP NAS Improper Authorization Vulnerability
QNAP Network Attached Storage (NAS) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-28799). QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. CISA remediation due date: 2022-04-21. If you need help checking exposure, call (864) 335-9223.