Incorrect Authorization Vulnerability Affects QNAP Operating System Versions
CVE-2023-50363
8.1HIGH
Summary
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later
Affected Version(s)
QTS < 5.1.6.2722 build 20240402
QuTS hero < h5.1.x
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 7.4 - (HIGH)
Vulnerability published.
Collectors
NVD DatabaseMitre Database
Credit
Aliz Hammond of watchTowr