QID 731053
Date Published: 2024-01-02
QID 731053: QNAP QTS Multiple Security Vulnerability (QSA-23-59,QSA-23-58)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.A buffer copy without checking size of input vulnerability has been reported to affect certain legacy versions of QTS.
Affected Versions:
QNAP QTS prior to version 5.1.0.2444 build 20230629.
QNAP QTS prior to version 5.0.1.2425 build 20230609.
QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may allow unauthenticated remote users to predict secret via unspecified vectors.
Solution
Vendor References
- QSA-23-58 -
www.qnap.com/en/security-advisory/qsa-23-58 - QSA-23-59 -
www.qnap.com/en/security-advisory/qsa-23-59
CVEs related to QID 731053
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-59 |
|