{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-23363","assignerOrgId":"2fd009eb-170a-4625-932b-17a53af1051f","state":"PUBLISHED","assignerShortName":"qnap","dateReserved":"2023-01-11T20:15:53.085Z","datePublished":"2023-09-22T03:50:42.730Z","dateUpdated":"2024-09-24T18:10:34.196Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"QTS","vendor":"QNAP Systems Inc.","versions":[{"lessThan":"4.3.6.2441 build 20230621","status":"affected","version":"4.3.*","versionType":"custom"},{"lessThan":"4.3.3.2420 build 20230621","status":"affected","version":"4.3.*","versionType":"custom"},{"lessThan":"4.2.6 build 20230621","status":"affected","version":"4.2.*","versionType":"custom"},{"lessThan":"4.3.4.2451 build 20230621","status":"affected","version":"4.3.*","versionType":"custom"},{"status":"unaffected","version":"4.5.*"},{"status":"unaffected","version":"5.*.*"}]}],"credits":[{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"H4lo"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.<br><br>We have already fixed the vulnerability in the following versions:<br>QTS 4.3.6.2441 build 20230621 and later<br>QTS 4.3.3.2420 build 20230621 and later<br>QTS 4.2.6 build 20230621 and later<br>QTS 4.3.4.2451 build 20230621 and later<br>"}],"value":"A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 4.3.6.2441 build 20230621 and later\nQTS 4.3.3.2420 build 20230621 and later\nQTS 4.2.6 build 20230621 and later\nQTS 4.3.4.2451 build 20230621 and later\n"}],"impacts":[{"capecId":"CAPEC-100","descriptions":[{"lang":"en","value":"CAPEC-100"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-120","description":"CWE-120","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"2fd009eb-170a-4625-932b-17a53af1051f","shortName":"qnap","dateUpdated":"2023-09-22T03:50:42.730Z"},"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-23-25"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"We have already fixed the vulnerability in the following versions:<br>QTS 4.3.6.2441 build 20230621 and later<br>QTS 4.3.3.2420 build 20230621 and later<br>QTS 4.2.6 build 20230621 and later<br>QTS 4.3.4.2451 build 20230621 and later<br>"}],"value":"We have already fixed the vulnerability in the following versions:\nQTS 4.3.6.2441 build 20230621 and later\nQTS 4.3.3.2420 build 20230621 and later\nQTS 4.2.6 build 20230621 and later\nQTS 4.3.4.2451 build 20230621 and later\n"}],"source":{"advisory":"QSA-23-25","discovery":"EXTERNAL"},"title":"QTS","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T10:28:40.542Z"},"title":"CVE Program Container","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-23-25","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-24T18:10:24.884937Z","id":"CVE-2023-23363","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-24T18:10:34.196Z"}}]}}