Record summary

CVE-2023-50362 has a selected CVSS score of 5.0 (medium).

Description

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 26, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List5.1.x to < 5.1.6.2722 build 20240402affected

Default status: unaffected

CVE Listh5.1.x to < h5.1.6.2734 build 20240414affected

Default status: unknown

CVE List5.1.x to < 5.1.6.2722 build 20240402affected

Default status: unknown

CVE Listh5.1.x to < h5.1.6.2734 build 20240414affected

References

2