Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2023-45026

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

  • Published: Feb 2, 2024
  • Updated: Feb 7, 2024
  • CVE: CVE-2023-45026
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.9
  • AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Software From Fixed in
qnap / qts 5.1.0.2348-build_20230325 5.1.0.2348-build_20230325.x
qnap / qts 5.1.0.2418-build_20230603 5.1.0.2418-build_20230603.x
qnap / qts 5.1.0.2399-build_20230515 5.1.0.2399-build_20230515.x
qnap / quts_hero h5.1.0.2409-build_20230525 h5.1.0.2409-build_20230525.x
qnap / qts 5.1.0.2466-build_20230721 5.1.0.2466-build_20230721.x
qnap / qts 5.1.1.2491-build_20230815 5.1.1.2491-build_20230815.x
qnap / qts 5.1.0.2444-build_20230629 5.1.0.2444-build_20230629.x
qnap / quts_hero h5.1.1.2488-build_20230812 h5.1.1.2488-build_20230812.x
qnap / quts_hero h5.1.0.2466-build_20230721 h5.1.0.2466-build_20230721.x
qnap / quts_hero h5.1.0.2453-build_20230708 h5.1.0.2453-build_20230708.x
qnap / quts_hero h5.1.0.2424-build_20230609 h5.1.0.2424-build_20230609.x
qnap / qts 5.1.3.2578-build_20231110 5.1.3.2578-build_20231110.x
qnap / qts 5.1.2.2533-build_20230926 5.1.2.2533-build_20230926.x
qnap / quts_hero h5.1.3.2578-build_20231110 h5.1.3.2578-build_20231110.x
qnap / quts_hero h5.1.2.2534-build_20230927 h5.1.2.2534-build_20230927.x
qnap / qutscloud c5.1.0.2498-build_20230822 c5.1.0.2498-build_20230822.x
qnap / quts_hero h5.1.4.2596-build_20231128 h5.1.4.2596-build_20231128.x
qnap / qts 5.1.5.2645 5.1.5.2645.x
qnap / qts 5.1.4.2596-build_20231128 5.1.4.2596-build_20231128.x
qnap / quts_hero h5.1.5.2647 h5.1.5.2647.x