First published: Fri Oct 06 2023(Updated: )
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.2.0.0823 and later
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qvpn | >=2.2.0<2.2.0.0823 |
We have already fixed the vulnerability in the following version: QVPN Windows 2.2.0.0823 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23371 is a cleartext transmission of sensitive information vulnerability in QVPN Device Client.
CVE-2023-23371 allows local authenticated administrators to read sensitive data through unspecified vectors.
CVE-2023-23371 has a severity rating of medium with a CVSS score of 4.4.
To fix CVE-2023-23371, update QVPN Device Client to version 2.2.0.0823 or higher.
More information about CVE-2023-23371 can be found at https://www.qnap.com/en/security-advisory/qsa-23-39.