=====================================================================

                              CERT-Renater

                    Note d'Information No. 2023/VULN388

_____________________________________________________________________

DATE                : 10/10/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Music Station versions prior
                                      to 5.3.22.

=====================================================================
https://www.qnap.com/en/security-advisory/qsa-23-28
_____________________________________________________________________

Security ID : QSA-23-28
Vulnerabilities in Music Station

     Release date : October 7, 2023

     CVE identifier : CVE-2023-23365|CVE-2023-23366

     Affected products: Music Station 5.3.x

Severity
High

Status
Resolved


Summary

Two path traversal vulnerabilities have been reported to affect Music
Station. If exploited, the vulnerabilities could allow authenticated
users to read the contents of unexpected files and expose sensitive
data via a network.

We have already fixed the vulnerability in the following version:

Affected Product        Fixed Version
Music Station 5.3.x     Music Station 5.3.22 and later


Recommendation

To fix the vulnerability, we recommend updating Music Station to the
latest version.

Updating Music Station

     Log on to QTS or QuTS hero as an administrator.
     Open App Center and then click .
     A search box appears.
     Type "Music Station" and then press ENTER.
     Music Station appears in the search results.
     Click Update.
     A confirmation message appears.
     Note: The Update button is not available if your Music Station is
already up to date.
     Click OK.
     The application is updated.


Attachment

     CVE-2023-23365.json
     CVE-2023-23366.json


Acknowledgements: Erik de Jong


Revision History:
V1.0 (October 07, 2023) - Published


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
