Nas
Vendor:
First CVE: Jun 7, 2013 · Active for 13 years
11
Total CVEs
More Total CVEs than 89% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nas over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2013
13 years ago
Most Recent CVE
Nov 20, 2021
1,710 days ago
CVE Severity & Scoring
Nas11 CVEs
73%
9%
18%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (81.8%)
Unknown2 (18.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High0 (0.0%)
Unknown2 (18.2%)
User Interaction
None2 (18.2%)
Unknown2 (18.2%)
Required7 (63.6%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None5 (45.5%)
Unknown2 (18.2%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0143MEDIUM cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitr | Jun 7, 2013 | 6.5 | 33 | NO | YES |
CVE-2021-28797CRITICAL A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute | Apr 14, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-34358HIGH We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | Nov 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-2501CRITICAL A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute | Feb 17, 2021 | 9.8 | 25 | NO | NO |
CVE-2021-34357MEDIUM A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious | Nov 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-38681MEDIUM A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject | Nov 20, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-38675MEDIUM A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote attackers to inject malicious c | Oct 1, 2021 | 5.4 | 18 | NO | NO |
CVE-2021-34356MEDIUM A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicio | Oct 1, 2021 | 5.4 | 18 | NO | NO |
CVE-2021-34355MEDIUM A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious | Oct 1, 2021 | 5.4 | 18 | NO | NO |
CVE-2021-34354MEDIUM A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicio | Oct 1, 2021 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Nas
Top CWEs
Versions
No cataloged versions.