Vulnerability in QTS, QuTS hero, and QuTScloud

Black Tiger

Addicted Member
Administrator
Moderator
Lid sinds
8 feb 2001
Berichten
34.838
Waarderingsscore
1.028
Punten
113
Leeftijd
60
Locatie
State Penitentiary
An OS command injection vulnerability has been reported to affect certain QNAP operating systems. If exploited, the vulnerability allows authenticated users to execute commands via network vector.

We have already fixed the vulnerability in the following versions:
  • QTS 5.0.1.2376 build 20230421 and later
  • QTS 4.5.4.2374 build 20230416 and later
  • QuTS hero h5.0.1.2376 build 20230421 and later
  • QuTS hero h4.5.4.2374 build 20230417 and later
  • QuTScloud c5.0.1.2374 and later
Security ID: QSA-23-18
Release date: September 16, 2023
Severity: High
CVE identifier: CVE-2023-23362
Affected products: QTS 5.0.1, 4.5.4; QuTS hero h5.0.1, h4.5.4; QuTScloud c5.0.1
 



Hosting Fun

Advertenties

Terug
Bovenaan Onderaan