CVE-2023-41279

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 2, 2024
Updated: Feb 6, 2024
CWE ID 121
CWE ID 120

Summary

CVE-2023-41279 is a recently identified buffer copy vulnerability that affects several QNAP operating system versions. This issue allows authenticated administrators to execute code via a network if they exploit the vulnerability, which occurs due to a failure to check the size of input data. The affected versions include QTS 5.1.2.2533 and earlier, QuTS hero h5.1.2.2534 and earlier, and QuTScloud c5.1.5.2651 and earlier. QNAP has already released patches to address this vulnerability in the listed versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share