02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 1.57% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 73.6% of scored records. A rank, not a probability.
- NVD base score
- 8.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2022-05-05 16:50Z4 YR AGO
- Last updated
- 2024-09-16 22:56Z1 YR AGO
- Reserved
- 2021-11-19
- Assigning CNA
- qnap
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 6.5)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Weaknesses
- CWE-59Improper Link Resolution Before File Access ('Link Following')Base
- Data version
- 5.1
- Document digest
- a1a3aa1e5aadf92469a1d488c347153c6c4a4ef67e4633d7476035bdb946407b
05 Affected products
PAIRS: 3VendorProductVersionsPlatforms
QNAP Systems Inc.QuTS hero< h4.5.4.1971 build 20220310, < h5.0.0.1986 build 20220324— QNAP Systems Inc.QTS< 4.3.4.1976 build 20220303, < 4.3.3.1945 build 20220303, < 4.2.6 build 20220304, < 4.3.6.1965 build 20220302, < 5.0.0.1986 build 20220324, < 4.5.4.1991 build 20220329— SRC: CNA
We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, and QTS:
QuTScloud c5.0.1.1998 and later
QuTS hero h4.5.4.1971 build 20220310 and later
QuTS hero h5.0.0.1986 build 20220324 and later
QTS 4.3.4.1976 build 20220303 and later
QTS 4.3.3.1945 build 20220303 and later
QTS 4.2.6 build 20220304 and later
QTS 4.3.6.1965 build 20220302 and later
QTS 5.0.0.1986 build 20220324 and later
QTS 4.5.4.1991 build 20220329 and later