QID 731131
Date Published: 2024-02-06
QID 731131: QNAP QTS Multiple Security Vulnerabilities (QSA-23-46) (QSA-23-53)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
.
Multiple OS command injection vulnerabilities have been reported to affect certain QNAP operating system versions.
Multiple buffer copies without checking the size of input vulnerabilities have been reported to affect certain QNAP operating system versions.
Affected Versions:
QNAP from 5.1.0.2348 build 20230325 to 5.1.3.2578 build 20231110.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
On successful exploitation, vulnerability may affect the Confidentiality, Integrity, and Availability of data.
Solution
Vendor References
- QSA-23-46 -
www.qnap.com/en/security-advisory/qsa-23-46 - QSA-23-53 -
www.qnap.com/en/security-advisory/qsa-23-53
CVEs related to QID 731131
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-53 |
|