Rewterz
Rewterz Threat Alert –North Korean APT Kimsuky Aka Black Banshee – Active IOCs
February 14, 2024
Rewterz
Rewterz Threat Alert – Raspberry Robin Malware Spreads Through Discord and Uses New Exploits – Active IOCs
February 14, 2024

Rewterz Threat Advisory – Multiple QNAP Products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-45035, CVE-2023-45037

QNAP QTS, QuTS hero and QuTScloud are vulnerable to a buffer overflow, caused by improper bounds checking. By sending a specially crafted request, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system.

CVE-2023-39302, CVE-2023-41281, CVE-2023-47567

QNAP QTS, QuTS hero and QuTScloud could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by an OS command injection flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.

CVE-2023-45026, CVE-2023-45027

QNAP QTS, QuTS hero and QuTScloud could allow a remote authenticated attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on the system.

CVE-2023-41275, CVE-2023-41276, CVE-2023-41277, CVE-2023-41278

QNAP QTS, QuTS hero and QuTScloud are vulnerable to a buffer overflow, caused by improper bounds checking. By sending a specially crafted request, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system.

CVE-2023-47564 CVSS:8

QNAP Qsync Central could allow a remote authenticated attacker to bypass security restrictions, caused by an incorrect permission assignment flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to read or modify the resource.

CVE-2023-47568 CVSS:8.8

QNAP QTS, QuTS hero and QuTScloud are vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

CVE-2023-45028 CVSS:5.5

QNAP QTS, QuTS hero and QuTScloud are vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2023-47561 CVSS:5.5

QNAP Photo Station is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

  • Denial of Service
  • Gain Access
  • Buffer Overflow
  • Security Bypass
  • Information Theft
  • Cross-Site Scripting

Indicators Of Compromise

CVE

  • CVE-2023-45035
  • CVE-2023-45037
  • CVE-2023-39302
  • CVE-2023-41281
  • CVE-2023-47567
  • CVE-2023-45026
  • CVE-2023-45027
  • CVE-2023-41275
  • CVE-2023-41276
  • CVE-2023-41277
  • CVE-2023-41278
  • CVE-2023-47564
  • CVE-2023-47568
  • CVE-2023-45028
  • CVE-2023-47561

Affected Vendors

QNAP

Affected Products

  • QNAP QTS 5.1
  • QNAP QTS 4.5
  • QNAP QuTS hero h5.1
  • QNAP QuTS hero h4.5
  • QNAP QuTScloud c5.1
  • QNAP Qsync Central 4.3
  • QNAP Qsync Central 4.4
  • QNAP Photo Station 6.4

Remediation

Refer to QNAP Security Advisory for patch, upgrade, or suggested workaround information.

CVE-2023-45035

CVE-2023-45037

CVE-2023-39302

CVE-2023-41281

CVE-2023-47567

CVE-2023-45026

CVE-2023-45027

CVE-2023-41275

CVE-2023-41276

CVE-2023-41277

CVE-2023-41278

CVE-2023-47564

CVE-2023-47568

CVE-2023-45028

CVE-2023-47561