02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.45% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 37.4% of scored records. A rank, not a probability.
- NVD base score
- 6.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2023-12-08 16:07Z2 YR AGO
- Last updated
- 2024-08-02 10:28Z2 YR AGO
- Reserved
- 2023-01-11
- Assigning CNA
- qnap
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 6.5)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Weaknesses
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Base
- Data version
- 5.1
- Document digest
- 709ab290abd7b2f5ffef971639158edb38ff4645d8266dfa41a027769b244c74
05 Affected products
PAIRS: 2VendorProductVersionsPlatforms
QNAP Systems Inc.QTS5.0.x to < 5.0.1.2425 build 20230609, 5.1.x to < 5.1.0.2444 build 20230629, 4.5.x to < 4.5.4.2467 build 20230718— QNAP Systems Inc.QuTS heroh5.1.x to < h5.1.0.2424 build 20230609, h5.0.x to < h5.0.1.2515 build 20230907, h4.5.x to < h4.5.4.2476 build 20230728— SRC: CNA
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444 build 20230629 and later
QTS 4.5.4.2467 build 20230718 and later
QuTS hero h5.1.0.2424 build 20230609 and later
QuTS hero h5.0.1.2515 build 20230907 and later
QuTS hero h4.5.4.2476 build 20230728 and later