7.2
CVSSv3

CVE-2023-23367

Published: 10/11/2023 Updated: 21/11/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTScloud c5.1.0.2498 and later

Vulnerable Product Search on Vulmon Subscribe to Product

qnap qts 5.0.1.2346

qnap qts 5.0.1.2277

qnap qts 5.0.1.2248

qnap qts 5.0.1.2234

qnap qts 5.0.1.2194

qnap qts 5.0.1.2173

qnap qts 5.0.1.2145

qnap qts 5.0.1.2137

qnap qts 5.0.1.2131

qnap qts 5.0.1.2079

qnap qts 5.0.1.2034

qnap qts 5.0.0.1870

qnap qts 5.0.0.1858

qnap qts 5.0.0.1853

qnap qts 5.0.0.1850

qnap qts 5.0.0.1837

qnap qts 5.0.0.1828

qnap qts 5.0.0.1808

qnap qts 5.0.0.1785

qnap qts 5.0.0.1716

qnap quts hero h5.0.1.2348

qnap quts hero h5.0.1.2277

qnap quts hero h5.0.1.2269

qnap quts hero h5.0.1.2248

qnap quts hero h5.0.1.2192

qnap quts hero h5.0.1.2045

qnap quts hero h5.0.0.2120

qnap quts hero h5.0.0.2069

qnap quts hero h5.0.0.2022

qnap quts hero h5.0.0.1986

qnap quts hero h5.0.0.1949

qnap quts hero h5.0.0.1900

qnap quts hero h5.0.0.1892

qnap quts hero h5.0.0.1856

qnap quts hero h5.0.0.1844

qnap quts hero h5.0.0.1772

qnap qutscloud c5.0.1.2148

qnap qutscloud c5.0.1.2044

qnap qutscloud c5.0.1.1998

qnap qutscloud c5.0.1.1949

qnap qutscloud c5.0.1.2374

qnap qutscloud c5.0.0.1919