漏洞标题
QTS,多媒体控制台和媒体流附加
漏洞描述信息
QTS、多媒体控制台和媒体串流附加功能
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
漏洞标题
QTS, Multimedia Console, and Media Streaming add-on
漏洞描述信息
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.2 ( 2023/05/04 ) and later
Multimedia Console 1.4.8 ( 2023/05/05 ) and later
QTS 5.1.0.2399 build 20230515 and later
QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.4.2451 build 20230621 and later
QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.6 build 20230621 and later
Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later
Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)
漏洞标题
QNAP Systems QTS 操作系统命令注入漏洞
漏洞描述信息
QNAP Systems QTS是中国威联通科技(QNAP Systems)公司的一个入门到中阶QNAP NAS 使用的操作系统。 QNAP Systems QTS 存在操作系统命令注入漏洞,该漏洞源于存在操作系统命令注入漏洞,可能允许攻击者通过网络执行命令。
CVSS信息
N/A
漏洞类别
授权问题