CVE-2023-23366: Music Station
Published Oct 6, 2023
·Updated
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later
Affected Software
1 affected component
QNAP Music Station>=5.3.0<5.3.22
Remediation
Information
We have already fixed the vulnerability in the following version:
Music Station 5.3.22 and later
Event History
Oct 6, 2023
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23366.
2
What software is affected by the vulnerability?
The Music Station software version 5.3.0 to 5.3.22 is affected by the vulnerability.
3
What is the severity of CVE-2023-23366?
The severity of CVE-2023-23366 is high, with a severity value of 6.5.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by authenticated users to read the contents of unexpected files and expose sensitive data via a network.
5
Has the vulnerability been fixed?
Yes, the vulnerability has been fixed in Music Station version 5.3.22.