Rewterz Threat Alert –North Korean APT Kimsuky Aka Black Banshee – Active IOCs
February 14, 2024Rewterz Threat Alert – Raspberry Robin Malware Spreads Through Discord and Uses New Exploits – Active IOCs
February 14, 2024Rewterz Threat Alert –North Korean APT Kimsuky Aka Black Banshee – Active IOCs
February 14, 2024Rewterz Threat Alert – Raspberry Robin Malware Spreads Through Discord and Uses New Exploits – Active IOCs
February 14, 2024Severity
Medium
Analysis Summary
CVE-2023-45035, CVE-2023-45037
QNAP QTS, QuTS hero and QuTScloud are vulnerable to a buffer overflow, caused by improper bounds checking. By sending a specially crafted request, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system.
CVE-2023-39302, CVE-2023-41281, CVE-2023-47567
QNAP QTS, QuTS hero and QuTScloud could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by an OS command injection flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-45026, CVE-2023-45027
QNAP QTS, QuTS hero and QuTScloud could allow a remote authenticated attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on the system.
CVE-2023-41275, CVE-2023-41276, CVE-2023-41277, CVE-2023-41278
QNAP QTS, QuTS hero and QuTScloud are vulnerable to a buffer overflow, caused by improper bounds checking. By sending a specially crafted request, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system.
CVE-2023-47564 CVSS:8
QNAP Qsync Central could allow a remote authenticated attacker to bypass security restrictions, caused by an incorrect permission assignment flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to read or modify the resource.
CVE-2023-47568 CVSS:8.8
QNAP QTS, QuTS hero and QuTScloud are vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2023-45028 CVSS:5.5
QNAP QTS, QuTS hero and QuTScloud are vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2023-47561 CVSS:5.5
QNAP Photo Station is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Impact
- Denial of Service
- Gain Access
- Buffer Overflow
- Security Bypass
- Information Theft
- Cross-Site Scripting
Indicators Of Compromise
CVE
- CVE-2023-45035
- CVE-2023-45037
- CVE-2023-39302
- CVE-2023-41281
- CVE-2023-47567
- CVE-2023-45026
- CVE-2023-45027
- CVE-2023-41275
- CVE-2023-41276
- CVE-2023-41277
- CVE-2023-41278
- CVE-2023-47564
- CVE-2023-47568
- CVE-2023-45028
- CVE-2023-47561
Affected Vendors
QNAP
Affected Products
- QNAP QTS 5.1
- QNAP QTS 4.5
- QNAP QuTS hero h5.1
- QNAP QuTS hero h4.5
- QNAP QuTScloud c5.1
- QNAP Qsync Central 4.3
- QNAP Qsync Central 4.4
- QNAP Photo Station 6.4
Remediation
Refer to QNAP Security Advisory for patch, upgrade, or suggested workaround information.