CVE-2023-45027
QTS, QuTS hero, QuTScloud
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QuTS hero h5.1.5.2647 build 20240118 and later
QuTScloud c5.1.5.2651 and later
Se ha informado que una vulnerabilidad de path traversal afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los administradores autenticados leer el contenido de archivos inesperados y exponer datos confidenciales a través de una red. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 5.1.5.2645 compilación 20240116 y posteriores QuTS hero h5.1.5.2647 compilación 20240118 y posteriores QuTScloud c5.1.5.2651 y posteriores
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-10-03 CVE Reserved
- 2024-02-02 CVE Published
- 2024-02-08 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
- CAPEC-126: Path Traversal
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-24-02 | 2024-02-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2348 Search vendor "Qnap" for product "Qts" and version "5.1.0.2348" | build_20230325 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2399 Search vendor "Qnap" for product "Qts" and version "5.1.0.2399" | build_20230515 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2418 Search vendor "Qnap" for product "Qts" and version "5.1.0.2418" | build_20230603 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2444 Search vendor "Qnap" for product "Qts" and version "5.1.0.2444" | build_20230629 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.0.2466 Search vendor "Qnap" for product "Qts" and version "5.1.0.2466" | build_20230721 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.1.2491 Search vendor "Qnap" for product "Qts" and version "5.1.1.2491" | build_20230815 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.2.2533 Search vendor "Qnap" for product "Qts" and version "5.1.2.2533" | build_20230926 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.3.2578 Search vendor "Qnap" for product "Qts" and version "5.1.3.2578" | build_20231110 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.4.2596 Search vendor "Qnap" for product "Qts" and version "5.1.4.2596" | build_20231128 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.1.5.2645 Search vendor "Qnap" for product "Qts" and version "5.1.5.2645" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2409 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2409" | build_20230525 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2424 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2424" | build_20230609 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2453 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2453" | build_20230708 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.0.2466 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.0.2466" | build_20230721 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.1.2488 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.1.2488" | build_20230812 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.2.2534 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.2.2534" | build_20230927 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.3.2578 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.3.2578" | build_20231110 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.4.2596 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.4.2596" | build_20231128 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.1.5.2647 Search vendor "Qnap" for product "Quts Hero" and version "h5.1.5.2647" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qutscloud Search vendor "Qnap" for product "Qutscloud" | c5.1.0.2498 Search vendor "Qnap" for product "Qutscloud" and version "c5.1.0.2498" | build_20230822 |
Affected
|