QID 731136
Date Published: 2024-02-07
QID 731136: QNAP QTS Incorrect Authorization Vulnerability (QSA-24-01)
QTS is the operating system for all entry-level and mid-level QNAP NAS models.
CVE-2023-32967: An incorrect authorization vulnerability has been reported to affect certain QNAP operating system versions.
Affected Versions:
QNAP from 4.5.1.1456 build 20201015 prior to 4.5.4.2627 build 20231225.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Successful exploitation of the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
Solution
The vendor has released a patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-24-01
Vendor References
- QSA-24-01 -
www.qnap.com/en/security-advisory/qsa-24-01
CVEs related to QID 731136
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-24-01 |
|