CVE-2023-32969: Network & Virtual Switch
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32969?
CVE-2023-32969 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2023-32969?
To fix CVE-2023-32969, update your QNAP network software to the latest versions: QuTScloud c5.1.5.2651, QTS 5.1.4.2596 build 20231128, or QuTS hero h5.1.4.2596 build 20231128.
Who is affected by CVE-2023-32969?
CVE-2023-32969 affects authenticated administrators using certain versions of QNAP QuTScloud, QTS, and QuTS hero software.
What could happen if CVE-2023-32969 is exploited?
If exploited, CVE-2023-32969 could allow authenticated administrators to inject malicious code via a network.
When was CVE-2023-32969 reported?
CVE-2023-32969 was reported recently and has been addressed in the latest software updates.