PT-2024-1637 · Qnap · Qts+1

Shahnawaz Shaikh

·

Published

2024-02-02

·

Updated

2024-02-08

·

CVE-2023-32967

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions QTS versions prior to 4.5.4.2627 build 20231225 QuTScloud versions prior to c5.1.5.2651
Description The issue is related to an incorrect authorization procedure in QNAP operating system versions, which could allow authenticated users to bypass intended access restrictions via a network.
Recommendations For QTS versions prior to 4.5.4.2627 build 20231225, update to QTS 4.5.4.2627 build 20231225 or later. For QuTScloud versions prior to c5.1.5.2651, update to QuTScloud c5.1.5.2651 or later.

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-01308
CVE-2023-32967

Affected Products

Qts
Qutscloud