SB2023090525 - Insufficient Entropy in QNAP QTS and QuTS hero
Published: September 5, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient Entropy (CVE-ID: CVE-2023-34973)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient entropy issue. A remote user can predict secrets via unspecified vectors.
Remediation
Install update from vendor's website.