← Back

CVE-2023-23369

nvd nist
Published: Nov 3, 2023Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia Console 1.4.8 ( 2023/05/05 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later

Affected (91)

3 products
Qts
Multimedia Console
Media Streaming Add On
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.1.0.2348 build_20230325
Configuration B
26 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.6.0895 build_20190328
Version 4.3.6.0907 build_20190409
Version 4.3.6.0923 build_20190425
Version 4.3.6.0944 build_20190516
Version 4.3.6.0959 build_20190531
Version 4.3.6.0979 build_20190620
Version 4.3.6.0993 build_20190704
Version 4.3.6.1013 build_20190724
Version 4.3.6.1033 build_20190813
Version 4.3.6.1070 build_20190919
Version 4.3.6.1154 build_20191212
Version 4.3.6.1218 build_20200214
Version 4.3.6.1263 build_20200330
Version 4.3.6.1286 build_20200422
Version 4.3.6.1333 build_20200608
Version 4.3.6.1411 build_20200825
Version 4.3.6.1446 build_20200929
Version 4.3.6.1620 build_20210322
Version 4.3.6.1663 build_20210504
Version 4.3.6.1711 build_20210621
Version 4.3.6.1750 build_20210730
Version 4.3.6.1831 build_20211019
Version 4.3.6.1907 build_20220103
Version 4.3.6.1965 build_20220302
Version 4.3.6.2050 build_20220526
Version 4.3.6.2232 build_20221124
Configuration C
13 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.4.0899 build_20190322
Version 4.3.4.1029 build_20190730
Version 4.3.4.1082 build_20190921
Version 4.3.4.1190 build_20200107
Version 4.3.4.1282 build_20200408
Version 4.3.4.1368 build_20200703
Version 4.3.4.1417 build_20200821
Version 4.3.4.1463 build_20201006
Version 4.3.4.1632 build_20210324
Version 4.3.4.1652 build_20210413
Version 4.3.4.1976 build_20220303
Version 4.3.4.2107 build_20220712
Version 4.3.4.2242 build_20221124
Configuration D
18 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.3.0174 build_20170503
Version 4.3.3.0868 build_20190322
Version 4.3.3.0998 build_20190730
Version 4.3.3.1051 build_20190921
Version 4.3.3.1098 build_20191107
Version 4.3.3.1161 build_20200109
Version 4.3.3.1252 build_20200409
Version 4.3.3.1315 build_20200611
Version 4.3.3.1386 build_20200821
Version 4.3.3.1432 build_20201006
Version 4.3.3.1624 build_20210416
Version 4.3.3.1677 build_20210608
Version 4.3.3.1693 build_20210624
Version 4.3.3.1799 build_20211008
Version 4.3.3.1864 build_20211212
Version 4.3.3.1945 build_20220303
Version 4.3.3.2057 build_20220623
Version 4.3.3.2211 build_20221124
Configuration E
14 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.2.6 build_20170517
Version 4.2.6 build_20190322
Version 4.2.6 build_20190730
Version 4.2.6 build_20190921
Version 4.2.6 build_20191107
Version 4.2.6 build_20200109
Version 4.2.6 build_20200421
Version 4.2.6 build_20200611
Version 4.2.6 build_20200821
Version 4.2.6 build_20210327
Version 4.2.6 build_20211215
Version 4.2.6 build_20220304
Version 4.2.6 build_20220623
Version 4.2.6 build_20221028
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 2.1.0
Version 2.1.1
Configuration G
5 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Configuration H
2 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 500.1.1.0
Version 500.1.1.1
Configuration I
10 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 500.0.0.0
Version 500.0.0.10
Version 500.0.0.1
Version 500.0.0.3
Version 500.0.0.4
Version 500.0.0.5
Version 500.0.0.6
Version 500.0.0.7
Version 500.0.0.8
Version 500.0.0.9

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.