Vulnerability Details CVE-2023-41291
A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following version:
QuFirewall 2.4.1 ( 2024/02/01 ) and later
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.3%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-41291
-
cpe:2.3:a:qnap:qufirewall:1.0.0
-
cpe:2.3:a:qnap:qufirewall:1.2.0
-
cpe:2.3:a:qnap:qufirewall:1.3.0
-
cpe:2.3:a:qnap:qufirewall:1.4.0
-
cpe:2.3:a:qnap:qufirewall:1.5.0
-
cpe:2.3:a:qnap:qufirewall:1.5.1
-
cpe:2.3:a:qnap:qufirewall:1.6.0
-
cpe:2.3:a:qnap:qufirewall:1.6.1
-
cpe:2.3:a:qnap:qufirewall:1.6.2
-
cpe:2.3:a:qnap:qufirewall:1.6.3
-
cpe:2.3:a:qnap:qufirewall:2.1.0
-
cpe:2.3:a:qnap:qufirewall:2.2.0
-
cpe:2.3:a:qnap:qufirewall:2.2.1
-
cpe:2.3:a:qnap:qufirewall:2.3.0
-
cpe:2.3:a:qnap:qufirewall:2.3.1
-
cpe:2.3:a:qnap:qufirewall:2.3.2
-
cpe:2.3:a:qnap:qufirewall:2.3.3
-
cpe:2.3:a:qnap:qufirewall:2.4.0