CVE-2023-32967

MEDIUM

QNAP QTS 4.5.4.2627 and QuTScloud < c5.1.5.2651 - Authenticated Improper Authorization

Title source: llm
STIX 2.1

Description

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0003
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-863
Status published
Products (13)
qnap/qts 4.5.4.1715 build_20210630
qnap/qts 4.5.4.1723 build_20210708
qnap/qts 4.5.4.1741 build_20210726
qnap/qts 4.5.4.1787 build_20210910
qnap/qts 4.5.4.1800 build_20210923
qnap/qts 4.5.4.1892 build_20211223
qnap/qts 4.5.4.1931 build_20220128
qnap/qts 4.5.4.2012 build_20220419
qnap/qts 4.5.4.2117 build_20220802
qnap/qts 4.5.4.2280 build_20230112
... and 3 more
Published Feb 02, 2024
Tracked Since Feb 18, 2026