本ページは qnap nas_proxy_server に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2021-34360 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 5.3 | 0.10% | 2022-05-26 | 2024-11-21 |
| CVE-2021-34361 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 5.3 | 0.35% | 2022-02-25 | 2024-11-21 |
| CVE-2021-34359 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later | [email protected] | 6.9 | 0.22% | 2022-02-25 | 2024-11-21 |
| CVE-2017-7639 | QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server. | [email protected] | 5.3 | 0.19% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7637 | QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges. | [email protected] | 9.8 | 3.25% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7636 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML. | [email protected] | 6.1 | 0.23% | 2018-06-05 | 2024-11-21 |
| CVE-2017-7635 | QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. | [email protected] | 8.8 | 0.16% | 2018-06-05 | 2024-11-21 |