CVE-2023-47564
Qsync Central
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.
We have already fixed the vulnerability in the following versions:
Qsync Central 4.4.0.15 ( 2024/01/04 ) and later
Qsync Central 4.3.0.11 ( 2024/01/11 ) and later
Se ha informado que una asignación incorrecta de permisos para una vulnerabilidad de recursos críticos afecta a Qsync Central. Si se explota, la vulnerabilidad podría permitir a los usuarios autenticados leer o modificar el recurso a través de una red. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: Qsync Central 4.4.0.15 (2024/01/04) y posteriores Qsync Central 4.3.0.11 (2024/01/11) y posteriores
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-06 CVE Reserved
- 2024-02-02 CVE Published
- 2024-02-05 First Exploit
- 2024-02-10 EPSS Updated
- 2024-08-29 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
- CAPEC-122: Privilege Abuse
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/C411e/CVE-2023-47564 | 2024-02-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-24-03 | 2024-02-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qsync Central Search vendor "Qnap" for product "Qsync Central" | >= 4.3.0.0 < 4.3.0.11 Search vendor "Qnap" for product "Qsync Central" and version " >= 4.3.0.0 < 4.3.0.11" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qsync Central Search vendor "Qnap" for product "Qsync Central" | >= 4.4.0.0 < 4.4.0.15 Search vendor "Qnap" for product "Qsync Central" and version " >= 4.4.0.0 < 4.4.0.15" | - |
Affected
|