← Back

CVE-2023-45027

nvd nist
Published: Feb 2, 2024Modified: Nov 21, 2024

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

Affected (20)

3 products
Qts
Quts Hero
Qutscloud
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 5.1.0.2348 build_20230325
Version 5.1.0.2399 build_20230515
Version 5.1.0.2418 build_20230603
Version 5.1.0.2444 build_20230629
Version 5.1.0.2466 build_20230721
Version 5.1.1.2491 build_20230815
Version 5.1.2.2533 build_20230926
Version 5.1.3.2578 build_20231110
Version 5.1.4.2596 build_20231128
Version 5.1.5.2645
Qnap
Version h5.1.0.2409 build_20230525
Version h5.1.0.2424 build_20230609
Version h5.1.0.2453 build_20230708
Version h5.1.0.2466 build_20230721
Version h5.1.1.2488 build_20230812
Version h5.1.2.2534 build_20230927
Version h5.1.3.2578 build_20231110
Version h5.1.4.2596 build_20231128
Version h5.1.5.2647
Version c5.1.0.2498 build_20230822

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.