A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-15456 A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5.
Fixes

Solution

QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.1663 Build 20210504 and later QTS 4.3.3.1624 Build 20210416 and later


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2024-09-16T23:01:07.180Z

Reserved: 2021-03-18T00:00:00

Link: CVE-2021-28800

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-24T07:15:07.580

Modified: 2024-11-21T06:00:13.670

Link: CVE-2021-28800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses