PT-2023-26878 · Qnap · Qnap Qutscloud+2

Aymen Borgi

+1

·

Published

2023-11-03

·

Updated

2023-11-14

·

CVE-2023-39301

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions QNAP QTS versions prior to 5.0.1.2514 build 20230906 QNAP QTS versions prior to 5.1.1.2491 build 20230815 QNAP QuTS hero h versions prior to h5.0.1.2515 build 20230907 QNAP QuTS hero h versions prior to h5.1.1.2488 build 20230812 QNAP QuTScloud c versions prior to c5.1.0.2498
Description A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network.
Recommendations For QNAP QTS versions prior to 5.0.1.2514 build 20230906, update to QTS 5.0.1.2514 build 20230906 or later. For QNAP QTS versions prior to 5.1.1.2491 build 20230815, update to QTS 5.1.1.2491 build 20230815 or later. For QNAP QuTS hero h versions prior to h5.0.1.2515 build 20230907, update to QuTS hero h5.0.1.2515 build 20230907 or later. For QNAP QuTS hero h versions prior to h5.1.1.2488 build 20230812, update to QuTS hero h5.1.1.2488 build 20230812 or later. For QNAP QuTScloud c versions prior to c5.1.0.2498, update to QuTScloud c5.1.0.2498 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-39301

Affected Products

Qnap Qts
Qnap Quts Hero
Qnap Qutscloud