CVE-2021-44051

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 5.0.0.1986 build 20220324 and later
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
qnapCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
qnapqts
5.0.0.1716 ≤
𝑥
< 5.0.0.1986
qnapqts
4.3.3.0174 ≤
𝑥
< 4.3.3.1945
qnapqts
4.3.4.0899 ≤
𝑥
< 4.3.4.1976
qnapqts
4.3.6.0895 ≤
𝑥
< 4.3.6.1965
qnapqts
4.4.0.0883 ≤
𝑥
< 4.5.4.1991
qnapqts
4.2.6:build_20170517
qnapqts
4.2.6:build_20190322
qnapqts
4.2.6:build_20190730
qnapqts
4.2.6:build_20190921
qnapqts
4.2.6:build_20191107
qnapqts
4.2.6:build_20200109
qnapqts
4.2.6:build_20200421
qnapqts
4.2.6:build_20200611
qnapqts
4.2.6:build_20200821
qnapqts
4.2.6:build_20210327
qnapqts
4.2.6:build_20211215
𝑥
= Vulnerable software versions