QID 731053

Date Published: 2024-01-02

QID 731053: QNAP QTS Multiple Security Vulnerability (QSA-23-59,QSA-23-58)

QTS is the operating system for all entry-level and mid-level QNAP NAS models.A buffer copy without checking size of input vulnerability has been reported to affect certain legacy versions of QTS.

Affected Versions:
QNAP QTS prior to version 5.1.0.2444 build 20230629.
QNAP QTS prior to version 5.0.1.2425 build 20230609.

QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Successful exploitation of the vulnerability may allow unauthenticated remote users to predict secret via unspecified vectors.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-59QSA-23-58

    CVEs related to QID 731053

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-59 URL Logo www.qnap.com/en/security-advisory/qsa-23-59