← Back

CVE-2023-32967

nvd nist
Published: Feb 2, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later

Affected (13)

Products: Qnap: Qts, Qutscloud
2 products
Qts
Qutscloud
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.5.4.1715 build_20210630
Version 4.5.4.1723 build_20210708
Version 4.5.4.1741 build_20210726
Version 4.5.4.1787 build_20210910
Version 4.5.4.1800 build_20210923
Version 4.5.4.1892 build_20211223
Version 4.5.4.1931 build_20220128
Version 4.5.4.2012 build_20220419
Version 4.5.4.2117 build_20220802
Version 4.5.4.2280 build_20230112
Version 4.5.4.2374 build_20230416
Version 4.5.4.2627
Version c5.1.0.2498 build_20230822

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.