Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.170121
Category:Privilege escalation
Title:QNAP QuTS hero Privilege Escalation Vulnerability (QSA-22-05)
Summary:QNAP QuTS hero is prone to a local privilege escalation; vulnerability, also known as dirty pipe.
Description:Summary:
QNAP QuTS hero is prone to a local privilege escalation
vulnerability, also known as dirty pipe.

Vulnerability Impact:
If exploited, this vulnerability allows an unprivileged user to
gain administrator privileges and inject malicious code.

Affected Software/OS:
QNAP QuTS hero version h5.x prior to h5.0.0.1986 build 20220324.

Solution:
Update to version h5.0.0.1986 build 20220324.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-0847
http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html
http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html
https://www.suse.com/support/kb/doc/?id=000020603
https://bugzilla.redhat.com/show_bug.cgi?id=2060795
https://dirtypipe.cm4all.com/
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.