Qnap
Qnap Helpdesk: vulnerabilidades y CVE
Qnap Helpdesk tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-2506 | Crítica (9.8) | 2.0% | ⚠ Explotación activa | 3 feb 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-50394 | Alta (7.7) | 0.31% | — | 7 mar 2025 | An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the… |
| CVE-2024-27125 | Media (4.8) | 0.25% | — | 6 sept 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the… |
| CVE-2021-28814 | Alta (8.8) | 1.2% | — | 11 jun 2021 | An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc.… |
| CVE-2020-2507 | Crítica (9.8) | 3.0% | — | 3 feb 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc.… |
| CVE-2020-2506 | Crítica (9.8) | 2.0% | ⚠ Explotación activa | 3 feb 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or… |
| CVE-2018-19948 | Media (6.5) | 0.30% | — | 11 sept 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions… |
| CVE-2018-19947 | Media (6.5) | 0.76% | — | 11 sept 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3… |
| CVE-2018-19946 | Media (5.9) | 0.32% | — | 11 sept 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the… |
| CVE-2020-2500 | Media (6.5) | 0.74% | — | 1 jul 2020 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to… |
| CVE-2018-0728 | Alta (7.5) | 1.3% | — | 4 dic 2019 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions. |
| CVE-2018-0714 | Crítica (9.8) | 2.3% | — | 13 ago 2018 | Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.