CVE-2023-23363
QTS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.6 build 20230621 and later
QTS 4.3.4.2451 build 20230621 and later
Se ha informado que una copia del búfer sin verificar el tamaño de la vulnerabilidad de entrada afecta el sistema operativo QNAP. Si se explota, la vulnerabilidad posiblemente permita a usuarios remotos ejecutar código a través de vectores no especificados. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 4.3.6.2441 compilación 20230621 y posteriores QTS 4.3.3.2420 compilación 20230621 y posteriores QTS 4.2.6 compilación 20230621 y posteriores QTS 4.3.4.2451 compilación 20230621 y posteriores
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-01-11 CVE Reserved
- 2023-09-22 CVE Published
- 2024-09-24 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
- CAPEC-100: Overflow Buffers
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-23-25 | 2023-09-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.3.3 < 4.3.3.2420 Search vendor "Qnap" for product "Qts" and version " >= 4.3.3 < 4.3.3.2420" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.3.4 < 4.3.4.245 Search vendor "Qnap" for product "Qts" and version " >= 4.3.4 < 4.3.4.245" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.3.6 < 4.3.6.2441 Search vendor "Qnap" for product "Qts" and version " >= 4.3.6 < 4.3.6.2441" | - |
Affected
|