Multiple vulnerabilities in QNAP operating systems



Published: 2023-03-30
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2022-27597
CVE-2022-27598
CVE-2023-23355
CWE-ID CWE-200
CWE-77
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
QuTScloud
Operating systems & Components / Operating system

QVP (QVR Pro appliances)
Hardware solutions / Firmware

QuTS hero
Hardware solutions / Firmware

QNAP QTS
Server applications / File servers (FTP/HTTP)

QVR
Client/Desktop applications / Other client software

Vendor QNAP Systems, Inc.

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Information disclosure

EUVDB-ID: #VU74194

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-27597

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

QuTScloud: All versions

QVP (QVR Pro appliances): All versions

QNAP QTS: before 5.0.1.2346 20230322

QuTS hero: before h5.0.1.2348 build 20230324

External links

http://www.qnap.com/en/security-advisory/qsa-23-06


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Information disclosure

EUVDB-ID: #VU74195

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-27598

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

QuTScloud: All versions

QVP (QVR Pro appliances): All versions

QNAP QTS: before 5.0.1.2346 20230322

QuTS hero: before h5.0.1.2348 build 20230324

External links

http://www.qnap.com/en/security-advisory/qsa-23-06


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Command Injection

EUVDB-ID: #VU74200

Risk: Medium

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-23355

CWE-ID: CWE-77 - Command injection

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to improper input validation. A remote user can pass specially crafted data to the application and execute arbitrary commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

QuTScloud: All versions

QVP (QVR Pro appliances): All versions

QVR: All versions

QNAP QTS: before 5.0.1.2346 20230322

QuTS hero: before h5.0.1.2348 build 20230324

External links

http://www.qnap.com/en/security-advisory/qsa-23-10


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###