QID 731133
Date Published: 2024-02-08
QID 731133: QNAP QTS Multiple Security Vulnerability (QSA-24-05)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
CVE-2023-47567: The OS command injection vulnerability could allow authenticated administrators to execute commands via a network.
CVE-2023-47568: The SQL injection vulnerability could allow authenticated users to inject malicious code via a network.
Affected Versions:
QNAP from 5.1.0.2348 build 20230325 prior to 5.1.5.2645 build 20240116.
QNAP from 4.5.1.1456 build 20201015 prior to 4.5.4.2627 build 20231225.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability may compromise Confidentiality, Integrity, and Availability of data.
- QSA-24-05 -
www.qnap.com/en/security-advisory/qsa-24-05
CVEs related to QID 731133
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-24-05 |
|