QID 731044
Date Published: 2023-12-28
QID 731044: QNAP QTS Buffer Overflow Vulnerability (QSA-23-31)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.A buffer copy without checking size of input vulnerability has been reported to affect certain legacy versions of QTS.
Affected Versions:
QNAP QTS prior to version 4.3.6.2441 build 20230621.
QNAP QTS prior to version 4.3.4.2451 build 20230621.
QNAP QTS prior to version 4.3.3.2420 build 20230621.
QNAP QTS prior to version 4.2.6 build 20230621.
QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may allow unauthenticated remote attacker to execute code via unspecified vectors.
Solution
Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-25
Vendor References
- QSA-23-25 -
www.qnap.com/en/security-advisory/qsa-23-25
CVEs related to QID 731044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-25 |
|