CVE-2023-32967
QTS, QuTScloud
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
02 feb 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
QTS 5.x, QuTS hero are not affected.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 4.5.4.2627 build 20231225 and later
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Productos afectados
QNAP Systems Inc. · QTSQNAP Systems Inc. · QuTScloudQNAP Systems Inc. · QuTS hero¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →