QNAP OS Versions Vulnerable to NULL Pointer Dereference Attack
CVE-2023-51368

6.5MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
6 September 2024

Summary

A NULL pointer dereference vulnerability has been identified in multiple QNAP operating system versions, which can be exploited to initiate a denial-of-service (DoS) attack through a network. This vulnerability poses a risk as it may allow an attacker to disrupt the functionality of affected systems. The issue has been addressed in recent updates, and users are strongly advised to upgrade to the latest versions, specifically QTS 5.1.6.2722 build 20240402 and later, as well as QuTS hero h5.1.6.2734 build 20240414 and later, to mitigate the risk.

Affected Version(s)

QTS 5.1.x < 5.1.6.2722 build 20240402

QuTS hero h5.1.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

chumen77
.