VYPR
Medium severity5.5NVD Advisory· Published Feb 2, 2024· Updated Jun 17, 2026

CVE-2023-41278

CVE-2023-41278

Description

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • Qnap/Qtsllm-fuzzy8 versions
    before 5.1.2.2533 build 20230926+ 7 more
    • (no CPE)range: before 5.1.2.2533 build 20230926
    • cpe:2.3:o:qnap:qts:5.1.0.2348:build_20230325:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.0.2399:build_20230515:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.0.2418:build_20230603:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.0.2444:build_20230629:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.0.2466:build_20230721:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.1.2491:build_20230815:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.1.2.2533:-:*:*:*:*:*:*
  • Qnap/Quts Herollm-fuzzy7 versions
    before h5.1.2.2534 build 20230927+ 6 more
    • (no CPE)range: before h5.1.2.2534 build 20230927
    • cpe:2.3:o:qnap:quts_hero:h5.1.0.2409:build_20230525:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.1.0.2424:build_20230609:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.1.0.2453:build_20230708:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.1.0.2466:build_20230721:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.1.1.2488:build_20230812:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.1.2.2534:-:*:*:*:*:*:*
  • Qnap/QuTScloudllm-fuzzy2 versions
    before c5.1.5.2651 and later+ 1 more
    • (no CPE)range: before c5.1.5.2651 and later
    • cpe:2.3:o:qnap:qutscloud:c5.1.0.2498:build_20230822:*:*:*:*:*:*
  • Range: 5.1.x
  • Range: h5.1.x
  • Range: c5.x.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.