7.2

CVE-2023-32968

QTS, QuTS hero

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2514 build 20230906 and later
QTS 5.1.2.2533 build 20230926 and later
QuTS hero h5.0.1.2515 build 20230907 and later
QuTS hero h5.1.2.2534 build 20230927 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.1.0.2348 Update build_20230325
Qnap ≫ Qts Version 5.1.0.2399 Update build_20230515
Qnap ≫ Qts Version 5.1.0.2418 Update build_20230603
Qnap ≫ Qts Version 5.1.0.2444 Update build_20230629
Qnap ≫ Qts Version 5.1.0.2466 Update build_20230721
Qnap ≫ Qts Version 5.1.1.2491 Update build_20230815
Qnap ≫ Qts Version 5.0.1.2034 Update build_20220515
Qnap ≫ Qts Version 5.0.1.2079 Update build_20220629
Qnap ≫ Qts Version 5.0.1.2131 Update build_20220820
Qnap ≫ Qts Version 5.0.1.2137 Update build_20220826
Qnap ≫ Qts Version 5.0.1.2145 Update build_20220903
Qnap ≫ Qts Version 5.0.1.2173 Update build_20221001
Qnap ≫ Qts Version 5.0.1.2194 Update build_20221022
Qnap ≫ Qts Version 5.0.1.2234 Update build_20221201
Qnap ≫ Qts Version 5.0.1.2248 Update build_20221215
Qnap ≫ Qts Version 5.0.1.2277 Update build_20230112
Qnap ≫ Qts Version 5.0.1.2346 Update build_20230322
Qnap ≫ Qts Version 5.0.1.2376 Update build_20230421
Qnap ≫ Qts Version 5.0.1.2425 Update build_20230609
Qnap ≫ Quts Hero Version h5.1.0.2409 Update build_20230525
Qnap ≫ Quts Hero Version h5.1.0.2424 Update build_20230609
Qnap ≫ Quts Hero Version h5.1.0.2453 Update build_20230708
Qnap ≫ Quts Hero Version h5.1.0.2466 Update build_20230721
Qnap ≫ Quts Hero Version h5.1.1.2488 Update build_20230812
Qnap ≫ Quts Hero Version h5.0.1.2045 Update build_20220526
Qnap ≫ Quts Hero Version h5.0.1.2192 Update build_20221020
Qnap ≫ Quts Hero Version h5.0.1.2248 Update build_20221215
Qnap ≫ Quts Hero Version h5.0.1.2269 Update build_20230104
Qnap ≫ Quts Hero Version h5.0.1.2277 Update build_20230112
Qnap ≫ Quts Hero Version h5.0.1.2348 Update build_20230324
Qnap ≫ Quts Hero Version h5.0.1.2376 Update build_20230421
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.76% 0.504
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 4.5 0.9 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://www.qnap.com/en/security-advisory/qsa-23-07
Vendor Advisory