Multimedia Console
Vendor:
First CVE: Dec 10, 2020 · Active for 5 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Multimedia Console over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2020
5 years ago
Most Recent CVE
Nov 3, 2023
994 days ago
CVE Severity & Scoring
Multimedia Console5 CVEs
20%
80%
All CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23369CRITICAL An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via | Nov 3, 2023 | 9.8 | 38 | NO | NO |
CVE-2023-23364CRITICAL A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execu | Sep 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-38684CRITICAL A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. | Nov 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-36195CRITICAL An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attacker | Apr 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-2493MEDIUM This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1 | Dec 10, 2020 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Multimedia Console
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.1 | 1 | 9.8 | 14.5% | 0 | 0 |
| 2.1.0 | 1 | 9.8 | 14.5% | 0 | 0 |
| 1.5.2 | 1 | 9.8 | 1.3% | 0 | 0 |
| 1.4.7 | 1 | 9.8 | 14.5% | 0 | 0 |
| 1.4.6 | 1 | 9.8 | 14.5% | 0 | 0 |
| 1.4.5 | 1 | 9.8 | 14.5% | 0 | 0 |
| 1.4.4 | 1 | 9.8 | 14.5% | 0 | 0 |
| 1.4.3 | 1 | 9.8 | 14.5% | 0 | 0 |