Vulnerability Details CVE-2023-32969
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 20231128 and later
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.3%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2023-32969
-
-
cpe:2.3:o:qnap:qts:5.1.0.2348
-
cpe:2.3:o:qnap:qts:5.1.0.2399
-
cpe:2.3:o:qnap:qts:5.1.0.2418
-
cpe:2.3:o:qnap:qts:5.1.0.2444
-
cpe:2.3:o:qnap:qts:5.1.0.2466
-
cpe:2.3:o:qnap:qts:5.1.1.2491
-
cpe:2.3:o:qnap:qts:5.1.2.2533
-
cpe:2.3:o:qnap:qts:5.1.3.2578
-
cpe:2.3:o:qnap:qts:5.1.4.2596
-
cpe:2.3:o:qnap:quts_hero:h5.1.0
-
cpe:2.3:o:qnap:quts_hero:h5.1.0.2409
-
cpe:2.3:o:qnap:quts_hero:h5.1.0.2424
-
cpe:2.3:o:qnap:quts_hero:h5.1.0.2453
-
cpe:2.3:o:qnap:quts_hero:h5.1.0.2466
-
cpe:2.3:o:qnap:quts_hero:h5.1.1.2488
-
cpe:2.3:o:qnap:quts_hero:h5.1.2.2534
-
cpe:2.3:o:qnap:quts_hero:h5.1.3.2578
-
cpe:2.3:o:qnap:quts_hero:h5.1.4.2596
-
cpe:2.3:o:qnap:qutscloud:c5.0.0.1919
-
cpe:2.3:o:qnap:qutscloud:c5.0.1
-
cpe:2.3:o:qnap:qutscloud:c5.0.1.1949
-
cpe:2.3:o:qnap:qutscloud:c5.0.1.1998
-
cpe:2.3:o:qnap:qutscloud:c5.0.1.2044
-
cpe:2.3:o:qnap:qutscloud:c5.0.1.2148
-
cpe:2.3:o:qnap:qutscloud:c5.0.1.2374
-
cpe:2.3:o:qnap:qutscloud:c5.1.0.2498