Description:
QNAP has published security advisories to address multiple vulnerabilities in QNAP products. The list of security updates can be found at:
https://www.qnap.com/en/security-advisory/QSA-23-41
https://www.qnap.com/en/security-advisory/QSA-23-42
Affected Systems:
- QNAP NAS devices running QTS operating system versions prior to 4.5.4.2467 build 20230718, 5.0.1.2425 build 20230609, 5.1.0.2444 build 20230629
- QNAP NAS devices running QuTS hero operating system versions prior to h4.5.4.2476 build 20230728, h5.0.1.2515 build 20230907, h5.1.0.2424 build 20230609
- QNAP NAS devices running QuTScloud version prior to c5.1.0.2498
For detailed information of the affected products, please refer to the corresponding security advisory at vendor's website.
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service or information disclosure on an affected system.
Recommendation:
Patches for affected products are available. System administrators of affected products should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
More Information:
- https://www.qnap.com/en/security-advisory/QSA-23-41
- https://www.qnap.com/en/security-advisory/QSA-23-42
- https://www.hkcert.org/security-bulletin/qnap-nas-multiple-vulnerabilities_20231016
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32970
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32973 (to CVE-2023-32974)