← Back

CVE-2023-23362

nvd nist
Published: Sep 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and later

Affected (5)

3 products
Qts
Quts Hero
Qutscloud
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
From 4.5.4 to 4.5.4.2374
From 5.0.1 to 5.0.1.2376
Qnap
From h4.5.4 to h4.5.4.2374
From h5.0.1 to h5.0.1.2376
From c5.0.1 to c5.0.1.2374

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.