CVE-2023-41274: QTS, QuTS hero, QuTScloud
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41274?
The severity of CVE-2023-41274 is currently classified as high due to its potential to enable denial-of-service attacks.
How do I fix CVE-2023-41274?
To fix CVE-2023-41274, users should upgrade to the latest version of QNAP QTS or QuTS that addresses this vulnerability.
Which QNAP operating system versions are affected by CVE-2023-41274?
CVE-2023-41274 affects specific versions of QNAP QTS and QuTS, including builds from 5.1.0.2348 to 5.1.2.2533.
What impact does CVE-2023-41274 have on QNAP devices?
If exploited, CVE-2023-41274 can allow authenticated administrators to execute denial-of-service attacks, compromising device availability.
Is CVE-2023-41274 exploitable remotely?
Yes, CVE-2023-41274 can be potentially exploited remotely over a network by authenticated users.