Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.151480
Category:General
Title:QNAP QuTS hero Multiple Vulnerabilities (QSA-23-22, QSA-23-54, QSA-23-64)
Summary:QNAP QuTS hero is prone to multiple vulnerabilities.
Description:Summary:
QNAP QuTS hero is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2022-43634: Vulnerability in Netatalk

- CVE-2023-39294: An OS command injection vulnerability has been reported to affect certain QNAP
operating system versions. If exploited, the vulnerability could allow authenticated
administrators to execute commands via a network.

- CVE-2023-39296: A prototype pollution vulnerability has been reported to affect certain QNAP
operating system versions. If exploited, the vulnerability could allow remote users to override
existing attributes with ones that have an incompatible type, which may cause the system to
crash.

Affected Software/OS:
QNAP QuTS hero version h5.1.x.

Solution:
Update to version h5.1.3.2578 build 20231110 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-43634
Debian Security Information: DSA-5503 (Google Search)
https://www.debian.org/security/2023/dsa-5503
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GEAFLA5L2SHOUFBAGUXIF2TZLGBXGJKT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZYWSGVA6WXREMB6PV56HAHKU7R6KPOP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SG6WZW5LXFVH3P7ZVZRGHUVJEMEFKQLI/
https://github.com/Netatalk/Netatalk/pull/186
https://www.zerodayinitiative.com/advisories/ZDI-23-094/
https://lists.debian.org/debian-lts-announce/2023/05/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-39294
https://www.qnap.com/en/security-advisory/qsa-23-54
Common Vulnerability Exposure (CVE) ID: CVE-2023-39296
https://www.qnap.com/en/security-advisory/qsa-23-64
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.