CVE-2023-32969: Network & Virtual Switch

Published Mar 8, 2024
·
Updated

A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.

We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

Affected Software

8 affected components
QNAP QuTScloud>c5.1.5.2651
QNAP QTS>5.1.4.2596 build 20231128
QNAP QuTS hero>h5.1.4.2596 build 20231128
QNAP QTS>=5.1.0<5.1.4.2596
QNAP QTS=5.1.4.2596
QNAP QuTS hero>=h5.1.0<h5.1.4.2596
QNAP QuTS hero=h5.1.4.2596
QNAP QuTScloud>=c5.0.0.1919<c5.1.5.2651

Remediation

Information

We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

Event History

Mar 8, 2024
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-32969?

CVE-2023-32969 is classified as a cross-site scripting (XSS) vulnerability.

2

How do I fix CVE-2023-32969?

To fix CVE-2023-32969, update your QNAP network software to the latest versions: QuTScloud c5.1.5.2651, QTS 5.1.4.2596 build 20231128, or QuTS hero h5.1.4.2596 build 20231128.

3

Who is affected by CVE-2023-32969?

CVE-2023-32969 affects authenticated administrators using certain versions of QNAP QuTScloud, QTS, and QuTS hero software.

4

What could happen if CVE-2023-32969 is exploited?

If exploited, CVE-2023-32969 could allow authenticated administrators to inject malicious code via a network.

5

When was CVE-2023-32969 reported?

CVE-2023-32969 was reported recently and has been addressed in the latest software updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203