QID 731055

Date Published: 2024-01-04

QID 731055: QNAP QTS Multiple Security Vulnerabilities (QSA-23-40,QSA-23-37,QSA-23-41)

QTS is the operating system for all entry-level and mid-level QNAP NAS models.

CVE-2023-23372: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.
CVE-2023-32971, CVE-2023-32972: A buffer copy without checking the size of input vulnerability has been reported to affect several QNAP operating system versions.
CVE-2023-32970: The null pointer dereference vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
CVE-2023-32973: The buffer copy without checking size of the input vulnerability could allow authenticated administrators to execute code via a network.

Affected Versions:
QNAP QTS prior to version 5.1.0.2444 build 20230629.
QNAP QTS prior to version 5.0.1.2425 build 20230609.
QNAP QTS prior to version 4.5.4.2467 build 20230718.

QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Successful exploitation of the vulnerability may allow authenticated remote attacker to inject malicious code via a network..

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-40QSA-23-37QSA-23-41

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-40 URL Logo www.qnap.com/en/security-advisory/qsa-23-40