QNAP OS Versions Vulnerable to NULL Pointer Dereference Attack
CVE-2023-51368
6.5MEDIUM
Summary
A NULL pointer dereference vulnerability has been identified in multiple QNAP operating system versions, which can be exploited to initiate a denial-of-service (DoS) attack through a network. This vulnerability poses a risk as it may allow an attacker to disrupt the functionality of affected systems. The issue has been addressed in recent updates, and users are strongly advised to upgrade to the latest versions, specifically QTS 5.1.6.2722 build 20240402 and later, as well as QuTS hero h5.1.6.2734 build 20240414 and later, to mitigate the risk.
Affected Version(s)
QTS 5.1.x < 5.1.6.2722 build 20240402
QuTS hero h5.1.x
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
chumen77