This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Qnap First view 2020-12-10
Product Multimedia Console Last view 2023-11-03
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:qnap:multimedia_console:*:*:*:*:*:*:*:* 3
cpe:2.3:a:qnap:multimedia_console:1.5.2:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:2.1.0:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:1.4.7:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:1.4.6:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:1.4.5:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:1.4.4:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:1.4.3:*:*:*:*:*:*:* 2
cpe:2.3:a:qnap:multimedia_console:2.1.1:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
9.8 2023-11-03 CVE-2023-23369

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia Console 1.4.8 ( 2023/05/05 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later

9.8 2023-09-22 CVE-2023-23364

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.

We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 ) and later Multimedia Console 1.4.7 ( 2023/03/20 ) and later

9.8 2021-11-13 CVE-2021-38684

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Multimedia Console: Multimedia Console 1.4.3 ( 2021/10/05 ) and later Multimedia Console 1.5.3 ( 2021/10/05 ) and later

6.1 2020-12-10 CVE-2020-2493

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.

CWE : Common Weakness Enumeration

%idName
25% (1) CWE-787 Out-of-bounds Write
25% (1) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
25% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
25% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...