First published: Fri Sep 06 2024(Updated: )
An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build 20240619 and later QTS 4.3.4.2814 build 20240618 and later QTS 4.3.3.2784 build 20240619 and later QTS 4.2.6 build 20240618 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =4.3.6.0895-build_20190328 | |
QNAP QTS | =4.3.6.0907-build_20190409 | |
QNAP QTS | =4.3.6.0923-build_20190425 | |
QNAP QTS | =4.3.6.0944-build_20190516 | |
QNAP QTS | =4.3.6.0959-build_20190531 | |
QNAP QTS | =4.3.6.0979-build_20190620 | |
QNAP QTS | =4.3.6.0993-build_20190704 | |
QNAP QTS | =4.3.6.1013-build_20190724 | |
QNAP QTS | =4.3.6.1033-build_20190813 | |
QNAP QTS | =4.3.6.1070-build_20190919 | |
QNAP QTS | =4.3.6.1154-build_20191212 | |
QNAP QTS | =4.3.6.1218-build_20200214 | |
QNAP QTS | =4.3.6.1263-build_20200330 | |
QNAP QTS | =4.3.6.1286-build_20200422 | |
QNAP QTS | =4.3.6.1333-build_20200608 | |
QNAP QTS | =4.3.6.1411-build_20200825 | |
QNAP QTS | =4.3.6.1446-build_20200929 | |
QNAP QTS | =4.3.6.1620-build_20210322 | |
QNAP QTS | =4.3.6.1663-build_20210504 | |
QNAP QTS | =4.3.6.1711-build_20210621 | |
QNAP QTS | =4.3.6.1750-build_20210730 | |
QNAP QTS | =4.3.6.1831-build_20211019 | |
QNAP QTS | =4.3.6.1907-build_20220103 | |
QNAP QTS | =4.3.6.1965-build_20220302 | |
QNAP QTS | =4.3.6.2050-build_20220526 | |
QNAP QTS | =4.3.6.2232-build_20221124 | |
QNAP QTS | =4.3.6.2441-build_20230621 | |
QNAP QTS | =4.3.6.2665-build_20240131 | |
QNAP QTS | =4.3.4.0899-build_20190322 | |
QNAP QTS | =4.3.4.1029-build_20190730 | |
QNAP QTS | =4.3.4.1082-build_20190921 | |
QNAP QTS | =4.3.4.1190-build_20200107 | |
QNAP QTS | =4.3.4.1282-build_20200408 | |
QNAP QTS | =4.3.4.1368-build_20200703 | |
QNAP QTS | =4.3.4.1417-build_20200821 | |
QNAP QTS | =4.3.4.1463-build_20201006 | |
QNAP QTS | =4.3.4.1632-build_20210324 | |
QNAP QTS | =4.3.4.1652-build_20210413 | |
QNAP QTS | =4.3.4.1976-build_20220303 | |
QNAP QTS | =4.3.4.2107-build_20220712 | |
QNAP QTS | =4.3.4.2242-build_20221124 | |
QNAP QTS | =4.3.4.2451-build_20230621 | |
QNAP QTS | =4.3.4.2675-build_20240131 | |
QNAP QTS | =4.3.3.0174-build_20170503 | |
QNAP QTS | =4.3.3.0868-build_20190322 | |
QNAP QTS | =4.3.3.0998-build_20190730 | |
QNAP QTS | =4.3.3.1051-build_20190921 | |
QNAP QTS | =4.3.3.1098-build_20191107 | |
QNAP QTS | =4.3.3.1161-build_20200109 | |
QNAP QTS | =4.3.3.1252-build_20200409 | |
QNAP QTS | =4.3.3.1315-build_20200611 | |
QNAP QTS | =4.3.3.1386-build_20200821 | |
QNAP QTS | =4.3.3.1432-build_20201006 | |
QNAP QTS | =4.3.3.1624-build_20210416 | |
QNAP QTS | =4.3.3.1677-build_20210608 | |
QNAP QTS | =4.3.3.1693-build_20210624 | |
QNAP QTS | =4.3.3.1799-build_20211008 | |
QNAP QTS | =4.3.3.1864-build_20211212 | |
QNAP QTS | =4.3.3.1945-build_20220303 | |
QNAP QTS | =4.3.3.2057-build_20220623 | |
QNAP QTS | =4.3.3.2211-build_20221124 | |
QNAP QTS | =4.3.3.2420-build_20230621 | |
QNAP QTS | =4.3.3.2644-build_20240131 | |
QNAP QTS | =4.2.6-build_20170517 | |
QNAP QTS | =4.2.6-build_20190322 | |
QNAP QTS | =4.2.6-build_20190730 | |
QNAP QTS | =4.2.6-build_20190921 | |
QNAP QTS | =4.2.6-build_20191107 | |
QNAP QTS | =4.2.6-build_20200109 | |
QNAP QTS | =4.2.6-build_20200421 | |
QNAP QTS | =4.2.6-build_20200611 | |
QNAP QTS | =4.2.6-build_20200821 | |
QNAP QTS | =4.2.6-build_20210327 | |
QNAP QTS | =4.2.6-build_20211215 | |
QNAP QTS | =4.2.6-build_20220304 | |
QNAP QTS | =4.2.6-build_20220623 | |
QNAP QTS | =4.2.6-build_20221028 | |
QNAP QTS | =4.2.6-build_20230621 | |
QNAP QTS | =4.2.6-build_20240131 |
We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build 20240619 and later QTS 4.3.4.2814 build 20240618 and later QTS 4.3.3.2784 build 20240619 and later QTS 4.2.6 build 20240618 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.