CVE-2023-32967
QTS, QuTScloud
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
QTS 5.x, QuTS hero are not affected.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 4.5.4.2627 build 20231225 and later
Se ha informado que una vulnerabilidad de autorización incorrecta afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los usuarios autenticados eludir las restricciones de acceso previstas a través de una red. QTS 5.x y QuTS hero no se ven afectados. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QuTScloud c5.1.5.2651 y posteriores QTS 4.5.4.2627 build 20231225 y posteriores
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-05-16 CVE Reserved
- 2024-02-02 CVE Published
- 2024-02-08 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-24-01 | 2024-02-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1715 Search vendor "Qnap" for product "Qts" and version "4.5.4.1715" | build_20210630 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1723 Search vendor "Qnap" for product "Qts" and version "4.5.4.1723" | build_20210708 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1741 Search vendor "Qnap" for product "Qts" and version "4.5.4.1741" | build_20210726 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1787 Search vendor "Qnap" for product "Qts" and version "4.5.4.1787" | build_20210910 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1800 Search vendor "Qnap" for product "Qts" and version "4.5.4.1800" | build_20210923 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1892 Search vendor "Qnap" for product "Qts" and version "4.5.4.1892" | build_20211223 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.1931 Search vendor "Qnap" for product "Qts" and version "4.5.4.1931" | build_20220128 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.2012 Search vendor "Qnap" for product "Qts" and version "4.5.4.2012" | build_20220419 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.2117 Search vendor "Qnap" for product "Qts" and version "4.5.4.2117" | build_20220802 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.2280 Search vendor "Qnap" for product "Qts" and version "4.5.4.2280" | build_20230112 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.2374 Search vendor "Qnap" for product "Qts" and version "4.5.4.2374" | build_20230416 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.5.4.2627 Search vendor "Qnap" for product "Qts" and version "4.5.4.2627" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qutscloud Search vendor "Qnap" for product "Qutscloud" | c5.1.0.2498 Search vendor "Qnap" for product "Qutscloud" and version "c5.1.0.2498" | build_20230822 |
Affected
|