QNAP NAS Multiple Vulnerabilities
Release Date:
29 Apr 2024
2803
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- QTS 4.5.4.2627 version prior to build 20231225
- QTS 5.1.3.2578 version prior to build 20231110
- QTS 5.1.4.2596 version prior to build 20231128
- QTS 5.1.6.2722 version prior to build 20240402
- QuFirewall version prior to 2.4.1 (2024/02/01)
- QuTS hero version prior to h4.5.4.2626 build 20231225
- QuTS hero version prior to h5.1.3.2578 build 20231110
- QuTS hero version prior to h5.1.6.2734 build 20240414
- QuTScloud version prior to c5.1.5.2651
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://www.qnap.com/en/security-advisory/qsa-24-14
- https://www.qnap.com/en/security-advisory/qsa-24-16
- https://www.qnap.com/en/security-advisory/qsa-24-17
- https://www.qnap.com/en/security-advisory/qsa-24-20
Vulnerability Identifier
- CVE-2023-41290
- CVE-2023-41291
- CVE-2023-50361
- CVE-2023-50362
- CVE-2023-50363
- CVE-2023-50364
- CVE-2023-51364
- CVE-2023-51365
- CVE-2024-21905
Source
Related Link
Share with