CVE-2023-39298

HIGH EPSS 3.8%
Published Sep 6, 20241y ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
High
Find Similar
Published Sep 6, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access data or perform actions that they should not be allowed to perform via unspecified vectors. QuTScloud, is not affected. We have already fixed the vulnerability in the following versions: QTS 5.2.0.2737 build 20240417 and later QuTS hero h5.2.0.2782 build 20240601 and later

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
3.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-862 Missing Authorization Authorization

Affected Products 32

VendorProductVersionRange
qnapqts5.1.0.2348any
qnapqts5.1.0.2399any
qnapqts5.1.0.2418any
qnapqts5.1.0.2444any
qnapqts5.1.0.2466any
qnapqts5.1.1.2491any
qnapqts5.1.2.2533any
qnapqts5.1.3.2578any
qnapqts5.1.4.2596any
qnapqts5.1.5.2645any
qnapqts5.1.5.2679any
qnapqts5.1.6.2722any
qnapqts5.1.7.2770any
qnapqts5.1.8.2823any
qnapqts5.2.0.2737any
qnapqts5.2.0.2744any
qnapquts_heroh5.1.0.2409any
qnapquts_heroh5.1.0.2424any
qnapquts_heroh5.1.0.2453any
qnapquts_heroh5.1.0.2466any
qnapquts_heroh5.1.1.2488any
qnapquts_heroh5.1.2.2534any
qnapquts_heroh5.1.3.2578any
qnapquts_heroh5.1.4.2596any
qnapquts_heroh5.1.5.2647any
qnapquts_heroh5.1.5.2680any
qnapquts_heroh5.1.6.2734any
qnapquts_heroh5.1.7.2770any
qnapquts_heroh5.1.7.2788any
qnapquts_heroh5.1.7.2794any
qnapquts_heroh5.1.8.2823any
qnapquts_heroh5.2.0.2737any

References 1

  • qnap.com https://www.qnap.com/en/security-advisory/qsa-24-28
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.