Page 1 of 1

es1640dc v2 - CWE Vulnerabilities

Posted: Mon May 31, 2021 5:35 pm
by Dmont
After scanning our QNAP es1640dc v2, a number of vulnerabilities are shown. We've updated to the latest firmware (2.1.1.0775) but the vulnerabilities are still there.

The CWE vulnerabilities are:
CWE-319, CWE-77, CWE-79, CWE-295 and CWE-200.

All the vulnerabilities have a solution of updating the firmware to version 4.x.x but this QNAP can't do that.

Can someone in the know please check those vulnerabilities and see if the current firmware is protecting us, we can then put this down to a false positive.

Thank you

Re: es1640dc v2 - CWE Vulnerabilities

Posted: Mon May 31, 2021 9:29 pm
by dolbyman
you would need to contact qnap..we have no idea what is fixed or might be fixed in future updates