A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: QuFirewall 2.4.1 ( 2024/02/01 ) and later
History

Mon, 12 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:qnap_systems_inc:qufirewall:2.4.x:*:*:*:*:*:*:*
Vendors & Products Qnap Systems Inc
Qnap Systems Inc qufirewall
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published: 2024-04-26T15:01:31.313Z

Updated: 2024-08-12T19:34:13.709Z

Reserved: 2023-08-28T09:45:52.367Z

Link: CVE-2023-41291

cve-icon Vulnrichment

Updated: 2024-08-02T18:54:05.184Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-26T15:15:46.680

Modified: 2024-04-26T15:32:22.523

Link: CVE-2023-41291

cve-icon Redhat

No data.