VYPR
Medium severity5.0NVD Advisory· Published Feb 2, 2024· Updated Jun 17, 2026

CVE-2023-32967

CVE-2023-32967

Description

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected.

We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19
  • Qnap/Qts13 versions
    cpe:2.3:o:qnap:qts:4.5.4.1715:build_20210630:*:*:*:*:*:*+ 12 more
    • cpe:2.3:o:qnap:qts:4.5.4.1715:build_20210630:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1723:build_20210708:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1741:build_20210726:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1787:build_20210910:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1800:build_20210923:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1892:build_20211223:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.1931:build_20220128:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.2012:build_20220419:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.2117:build_20220802:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.2280:build_20230112:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.2374:build_20230416:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*
    • (no CPE)range: 4.5.4.2627 build 20231225 and later
  • Qnap/QuTScloud2 versions
    cpe:2.3:o:qnap:qutscloud:c5.1.0.2498:build_20230822:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:qnap:qutscloud:c5.1.0.2498:build_20230822:*:*:*:*:*:*
    • (no CPE)range: c5.1.5.2651 and later
  • Range: 4.5.x
  • Range: h5.1.x
  • Range: c5.x.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.