QID 731060
Date Published: 2024-01-18
QID 731060: QNAP QTS OS Command Injection Vulnerability (QSA-23-18)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
CVE-2023-23362: An OS command injection vulnerability has been reported to affect certain QNAP operating systems.
Affected Versions:
QNAP QTS version 5.0.1.2034 build 20220515 to prior version 5.0.1.2376 build 20230421.
QNAP QTS v ersion 4.5.4.1715 build 20210630 to prior version 4.5.4.2374 build 20230416.
QID Detection Logic:
This QID checks for vulnerable versions of the QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may allow authenticated remote attackers to inject malicious code via a network..
Solution
The vendor has released a patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-18
Vendor References
- QSA-23-18 -
www.qnap.com/en/security-advisory/qsa-23-18
CVEs related to QID 731060
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-18 | asdf |
|