CVE-2023-51368: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51368?
The severity of CVE-2023-51368 is significant as it allows for denial-of-service (DoS) attacks.
How do I fix CVE-2023-51368?
To fix CVE-2023-51368, update your QNAP operating system to the latest patched version listed in the advisory.
Which QNAP operating system versions are affected by CVE-2023-51368?
CVE-2023-51368 affects multiple versions of QNAP QTS and QuTS hero, including versions prior to the most recent fixes.
Can CVE-2023-51368 be exploited remotely?
Yes, CVE-2023-51368 can be exploited remotely via a network, potentially leading to system downtime.
Is there a workaround for CVE-2023-51368?
There are no official workarounds for CVE-2023-51368; the recommended solution is to upgrade to the patched versions.