PT-2023-8518 · Qnap · Qsync Central

C411E

·

Published

2023-11-06

·

Updated

2024-02-09

·

CVE-2023-47564

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qsync Central versions prior to 4.3.0.11 Qsync Central versions prior to 4.4.0.15
Description The issue is related to an incorrect permission assignment for a critical resource in Qsync Central. This could allow an authenticated user to read or modify the resource via a network.
Recommendations For Qsync Central versions prior to 4.3.0.11, update to version 4.3.0.11 or later. For Qsync Central versions prior to 4.4.0.15, update to version 4.4.0.15 or later.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2024-01086
CVE-2023-47564

Affected Products

Qsync Central