Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-28812

Опубликовано: 03 июн. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*
Версия до 5.5.4 (исключая)
cpe:2.3:o:qnap:qts:4.5.2:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*
Версия до 5.5.4 (исключая)
cpe:2.3:o:qnap:quts_hero:h4.5.2:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*
Версия до 5.5.4 (исключая)
cpe:2.3:o:qnap:qutscloud:c4.5.4:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02363
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.

EPSS

Процентиль: 85%
0.02363
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
CWE-77