QID 731051

Date Published: 2024-01-02

QID 731051: QNAP QTS Server-Side Request Forgery (SSRF) Vulnerability (QSA-23-51)

QTS (QNAP Turbo NAS System) is a Turbo NAS Operating System, providing file storage, backup, disaster recovery, security management and virtualization applications for businesses; multimedia applications.

CVE-2022-27600: A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions.

Affected versions:
QTS 5.1.1.2491 build 20230815 and later
QTS 5.0.1.2514 build 20230906 and later

QID Detection Logic:
This unauthenticated detection detects vulnerable versions depending on the version disclosed by making a call to the authLogin.cgi webpage.

Successful exploitation of this vulnerability could allow authenticated users to read application data via a network.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    QNAP has confirmed these vulnerabilities and released updated software. Customers are advised to refer to QSA-23-51 for more information pertaining to these updates.
    Vendor References

    CVEs related to QID 731051

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-51 URL Logo www.qnap.com/en/security-advisory/qsa-23-51