Prototype Pollution Vulnerability Affects QNAP Operating System Versions

CVE-2023-39296
7.5HIGH

Key Information

Vendor
QNAP
Status
QTS
QuTS hero
Vendor
CVE Published:
5 January 2024

Summary

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later

Affected Version(s)

QTS < 5.1.3.2578 build 20231110

QuTS hero < h5.1.x

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Anonymous working with SSD Secure Disclosure
.