QID 731063
Date Published: 2024-01-18
QID 731063: QNAP QTS OS Path Traversal Vulnerability (QSA-23-42)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.A buffer copy without checking size of input vulnerability has been reported to affect certain legacy versions of QTS.
Affected Versions:
QNAP QTS version 5.1.0.2348 build 20230325 prior to version 5.1.0.2444 build 20230629
QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may allow users to read and expose sensitive data via a network.
Solution
Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-42
Vendor References
- QSA-23-42 -
www.qnap.com/en/security-advisory/qsa-23-42
CVEs related to QID 731063
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-42 |
|