PT-2023-26878 · Qnap · Qnap Qutscloud+2
Aymen Borgi
+1
·
Publicado
2023-11-03
·
Atualizado
2023-11-14
·
CVE-2023-39301
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP QTS versions prior to 5.0.1.2514 build 20230906
QNAP QTS versions prior to 5.1.1.2491 build 20230815
QNAP QuTS hero h versions prior to h5.0.1.2515 build 20230907
QNAP QuTS hero h versions prior to h5.1.1.2488 build 20230812
QNAP QuTScloud c versions prior to c5.1.0.2498
Description
A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network.
Recommendations
For QNAP QTS versions prior to 5.0.1.2514 build 20230906, update to QTS 5.0.1.2514 build 20230906 or later.
For QNAP QTS versions prior to 5.1.1.2491 build 20230815, update to QTS 5.1.1.2491 build 20230815 or later.
For QNAP QuTS hero h versions prior to h5.0.1.2515 build 20230907, update to QuTS hero h5.0.1.2515 build 20230907 or later.
For QNAP QuTS hero h versions prior to h5.1.1.2488 build 20230812, update to QuTS hero h5.1.1.2488 build 20230812 or later.
For QNAP QuTScloud c versions prior to c5.1.0.2498, update to QuTScloud c5.1.0.2498 or later.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud