QID 731132
Date Published: 2024-02-06
QID 731132: QNAP QTS Multiple Security Vulnerability (QSA-24-02)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
CVE-2023-45026 and CVE-2023-45027: The path traversal vulnerabilities could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
CVE-2023-45028: The uncontrolled resource consumption vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
CVE-2023-47566: An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
Affected Versions:
QNAP from 5.1.0.2348 build 20230325 to 5.1.4.2596 build 20231128.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may compromise Confidentiality, Integrity, and Availability of data.
- QSA-24-02 -
www.qnap.com/en/security-advisory/qsa-24-02 - QSA-24-04 -
www.qnap.com/en/security-advisory/qsa-24-04
CVEs related to QID 731132
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-24-02 |
|