QID 731070
Date Published: 2024-01-18
QID 731070: QNAP QTS OS Multiple Security Vulnerabilities (QSA-23-27)
QTS is the operating system for all entry-level and mid-level QNAP NAS models. A buffer copy without checking the size of input vulnerability has been reported to affect certain legacy versions of QTS.
Multiple buffer copy without checking size of input vulnerabilities have been reported to affect certain QNAP operating system versions.
.
Affected Versions:
QNAP QTS version 5.1.0.2348 build 20230325 to version prior 5.1.4.2596 build 20231128
QID Detection Logic:
This QID checks for vulnerable versions of the QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may compromise Confidentiality, Integrity, and Availability of data.
Solution
Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-27
Vendor References
- QSA-23-27 -
www.qnap.com/en/security-advisory/qsa-23-27
CVEs related to QID 731070
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-27 |
|