A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.
We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.1 ( 2023/03/29 ) and later
Multimedia Console 1.4.7 ( 2023/03/20 ) and later
References
Link | Resource |
---|---|
https://www.qnap.com/en/security-advisory/qsa-23-29 | Vendor Advisory |
https://www.qnap.com/en/security-advisory/qsa-23-29 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.qnap.com/en/security-advisory/qsa-23-29 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
26 Sep 2023, 13:13
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:qnap:multimedia_console:*:*:*:*:*:*:*:* | |
First Time |
Qnap multimedia Console
Qnap |
|
References | (MISC) https://www.qnap.com/en/security-advisory/qsa-23-29 - Vendor Advisory | |
CWE | CWE-120 |
22 Sep 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-22 04:15
Updated : 2024-11-21 07:46
NVD link : CVE-2023-23364
Mitre link : CVE-2023-23364
CVE.ORG link : CVE-2023-23364
JSON object : View
Products Affected
qnap
- multimedia_console
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')