CVE-2023-41279: QTS, QuTS hero, QuTScloud
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41279?
CVE-2023-41279 is classified as a critical vulnerability that could allow authenticated administrators to execute code remotely.
How do I fix CVE-2023-41279?
To fix CVE-2023-41279, upgrade your QNAP QTS or QuTS hero to the latest patched versions provided by QNAP.
Which QNAP versions are affected by CVE-2023-41279?
CVE-2023-41279 affects multiple versions including QTS versions 5.1.0.2348, 5.1.0.2399, 5.1.0.2418, and others.
Can I exploit CVE-2023-41279 without authentication?
No, CVE-2023-41279 requires authenticated access to exploit the vulnerability.
What type of vulnerability is CVE-2023-41279?
CVE-2023-41279 is a buffer copy without checking size of input vulnerability.