« Volver al listado

CVE-2023-32967

Estado: ModificadaMedia (6.5)—

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected.

We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32967",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-32967",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-26T14:26:51.649493Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTScloud",
          "versions": [
            {
              "status": "affected",
              "version": "c5.x.x",
              "lessThan": "c5.1.5.2651",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QTS",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.x",
              "lessThan": "4.5.4.2627 build 20231225",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "5.1.x"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTS hero",
          "versions": [
            {
              "status": "unaffected",
              "version": "h5.1.x"
            },
            {
              "status": "unaffected",
              "version": "h4.5.x"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-02T16:15:46.573",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.\nQTS 5.x, QuTS hero are not affected.\n\nWe have already fixed the vulnerability in the following versions:\nQuTScloud c5.1.5.2651 and later\nQTS 4.5.4.2627 build 20231225 and later\n"
    },
    {
      "lang": "es",
      "value": "Se ha informado que una vulnerabilidad de autorización incorrecta afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los usuarios autenticados eludir las restricciones de acceso previstas a través de una red. QTS 5.x y QuTS hero no se ven afectados. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QuTScloud c5.1.5.2651 y posteriores QTS 4.5.4.2627 build 20231225 y posteriores "
    }
  ],
  "lastModified": "2026-06-17T05:59:55.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1715:build_20210630:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AA3560E-1778-4278-AD5A-6EB3A63A39A5"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1723:build_20210708:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39E9AF51-0254-472F-B31F-6ADF1848CBD6"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1741:build_20210726:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBB29CD6-B6BC-4C3E-AD44-8D822D10093C"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1787:build_20210910:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7B98F82-9246-496F-8B15-6F320F8E921F"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1800:build_20210923:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE7D1FD6-7D8D-4884-AE7B-5C0BC4E39F69"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1892:build_20211223:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1692CA79-1C6D-4BF8-B49E-3539FCE3E165"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1931:build_20220128:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C15A236A-4C43-4489-B6F3-EBC9AD786F77"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2012:build_20220419:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECE79BCD-8F86-46B1-A3C1-AC503DE1876F"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2117:build_20220802:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8303B319-7EA7-42BC-9246-6EBF81DE4545"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2280:build_20230112:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E0F4CCC-F4A5-407D-BA2E-2BBCBA6B731A"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2374:build_20230416:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D3AE695-CEEB-4A0C-A751-9172781B776B"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "320AEB7E-E07B-42AE-8F71-795A516BA5EA"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qutscloud:c5.1.0.2498:build_20230822:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C50B05E2-8F25-4CA7-84FE-F5C510C83FE1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}