CVE-2023-39296
QTS, QuTS hero
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
Se ha informado que un prototipo de vulnerabilidad de contaminación afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los usuarios anular atributos existentes por otros que tengan un tipo incompatible, lo que puede provocar una falla en la red. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 5.1.3.2578 compilación 20231110 y posteriores QuTS hero h5.1.3.2578 compilación 20231110 y posteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-27 CVE Reserved
- 2024-01-05 CVE Published
- 2024-01-12 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CAPEC
- CAPEC-77: Manipulating User-Controlled Variables
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-23-64 | 2024-01-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2348 Search vendor "Qnap" for product "Qts" and version "5.1.0.2348" | build_20230325 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2399 Search vendor "Qnap" for product "Qts" and version "5.1.0.2399" | build_20230515 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2418 Search vendor "Qnap" for product "Qts" and version "5.1.0.2418" | build_20230603 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2444 Search vendor "Qnap" for product "Qts" and version "5.1.0.2444" | build_20230629 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2466 Search vendor "Qnap" for product "Qts" and version "5.1.0.2466" | build_20230721 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.1.2491 Search vendor "Qnap" for product "Qts" and version "5.1.1.2491" | build_20230815 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.2.2533 Search vendor "Qnap" for product "Qts" and version "5.1.2.2533" | build_20230926 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2409 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2409" | build_20230525 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2424 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2424" | build_20230609 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2453 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2453" | build_20230708 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2466 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2466" | build_20230721 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.1.2488 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.1.2488" | build_20230812 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.2.2534 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.2.2534" | build_20230927 |
Affected
|