CVE-2023-32968: QNAP QTS

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.2.2534 build 20230927 and later

Affected products

  • QNAP QTS: version 5.1.0.2348 only; version 5.1.0.2399 only; version 5.1.0.2418 only; version 5.1.0.2444 only; version 5.1.0.2466 only; version 5.1.1.2491 only; …
  • QNAP Quts Hero: version h5.1.0.2409 only; version h5.1.0.2424 only; version h5.1.0.2453 only; version h5.1.0.2466 only; version h5.1.1.2488 only; version h5.0.1.2045 only; …

Published 2023-12-08. Last modified 2026-06-17.