7.2

CVE-2023-41280

QTS, QuTS hero, QuTScloud

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.1.2.2533 build 20230926 and later
QuTS hero h5.1.2.2534 build 20230927 and later
QuTScloud c5.1.5.2651 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.1.0.2348 Update build_20230325
Qnap ≫ Qts Version 5.1.0.2399 Update build_20230515
Qnap ≫ Qts Version 5.1.0.2418 Update build_20230603
Qnap ≫ Qts Version 5.1.0.2444 Update build_20230629
Qnap ≫ Qts Version 5.1.0.2466 Update build_20230721
Qnap ≫ Qts Version 5.1.1.2491 Update build_20230815
Qnap ≫ Qts Version 5.1.2.2533 Update -
Qnap ≫ Quts Hero Version h5.1.0.2409 Update build_20230525
Qnap ≫ Quts Hero Version h5.1.0.2424 Update build_20230609
Qnap ≫ Quts Hero Version h5.1.0.2453 Update build_20230708
Qnap ≫ Quts Hero Version h5.1.0.2466 Update build_20230721
Qnap ≫ Quts Hero Version h5.1.1.2488 Update build_20230812
Qnap ≫ Quts Hero Version h5.1.2.2534 Update -
Qnap ≫ Qutscloud Version c5.1.0.2498 Update build_20230822
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.58% 0.431
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 5.5 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

https://www.qnap.com/en/security-advisory/qsa-23-38
Vendor Advisory