Lucene search

K
nvd[email protected]NVD:CVE-2023-32973
HistoryOct 13, 2023 - 8:15 p.m.

CVE-2023-32973

2023-10-1320:15:09
CWE-120
CWE-121
CWE-787
web.nvd.nist.gov
1
cve-2023-32973
qnap os
buffer copy vulnerability
authenticated administrators
code execution
network exploit
qts
quts hero
qutscloud

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

27.8%

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444 build 20230629 and later
QTS 4.5.4.2467 build 20230718 and later
QuTS hero h5.0.1.2515 build 20230907 and later
QuTS hero h5.1.0.2424 build 20230609 and later
QuTS hero h4.5.4.2476 build 20230728 and later
QuTScloud c5.1.0.2498 and later

Affected configurations

Nvd
Node
qnapqtsRange4.5.14.5.4.2467
OR
qnapqtsRange5.0.0.17165.0.1.2425
OR
qnapqtsRange5.1.05.1.0.2444
OR
qnapquts_heroRangeh4.5.0h4.5.4.2476
OR
qnapquts_heroRangeh5.0.0h5.0.1.2515
OR
qnapquts_heroRangeh5.1.0h5.1.0.2424
OR
qnapqutscloudRangec5.0.0.1919c5.1.0.2498
VendorProductVersionCPE
qnapqts*cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
qnapquts_hero*cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
qnapqutscloud*cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

27.8%