QID 731135
Date Published: 2024-02-07
QID 731135: QNAP QTS Multiple Security Vulnerability (QSA-23-33)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
CVE-2023-39302: The OS command injection vulnerability could allow authenticated administrators to execute commands via a network.
CVE-2023-39303: The improper authentication vulnerability could allow users to compromise the security of the system via a network.
Affected Versions:
QNAP from 5.1.0.2348 build 20230325 prior to 5.1.3.2578 build 20231110 .
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
On successful exploitation, vulnerability may affect the Confidentiality, Integrity, and Availability of data.
Solution
The vendor has released a patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-33
Vendor References
- QSA-23-33 -
www.qnap.com/en/security-advisory/qsa-23-33
CVEs related to QID 731135
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-33 |
|