Lucene search

K
cve[email protected]CVE-2023-47564
HistoryFeb 02, 2024 - 4:15 p.m.

CVE-2023-47564

2024-02-0216:15:52
CWE-732
web.nvd.nist.gov
8
cve-2023-47564
qsync central
vulnerability
permission assignment
network access

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.

We have already fixed the vulnerability in the following versions:
Qsync Central 4.4.0.15 ( 2024/01/04 ) and later
Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

Affected configurations

NVD
Node
qnapqsync_centralRange4.3.0.04.3.0.11
OR
qnapqsync_centralRange4.4.0.04.4.0.15

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Qsync Central",
    "vendor": "QNAP Systems Inc.",
    "versions": [
      {
        "lessThan": "4.4.0.15 ( 2024/01/04 )",
        "status": "affected",
        "version": "4.4.x.x",
        "versionType": "custom"
      },
      {
        "lessThan": "4.3.0.11 ( 2024/01/11 )",
        "status": "affected",
        "version": "4.3.x.x",
        "versionType": "custom"
      }
    ]
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

Related for CVE-2023-47564