CVE-2023-41292: QTS, QuTS hero, QuTScloud
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41292?
CVE-2023-41292 is considered a significant vulnerability that could allow authenticated administrators to execute code via a network.
Which QNAP versions are affected by CVE-2023-41292?
CVE-2023-41292 affects several QNAP QTS and QuTS hero versions, including builds from 5.1.0.2348 to 5.1.4.2596 and corresponding QuTS hero versions.
How do I fix CVE-2023-41292?
To mitigate CVE-2023-41292, update your QNAP device to the latest version that includes the fix for this vulnerability.
What type of vulnerability is CVE-2023-41292?
CVE-2023-41292 is a buffer copy without checking the size of input vulnerability.
Who can exploit CVE-2023-41292?
CVE-2023-41292 can be exploited by authenticated administrators, making it a concern for security controls in enterprise environments.