← Back

CVE-2023-34979

nvd nist
Published: Sep 6, 2024Modified: Sep 17, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.5.4.2790 build 20240605 and later QuTS hero h4.5.4.2790 build 20240606 and later

Affected (28)

Products: Qnap: Qts, Quts Hero
2 products
Qts
Quts Hero
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.5.4.1715 build_20210630
Version 4.5.4.1723 build_20210708
Version 4.5.4.1741 build_20210726
Version 4.5.4.1787 build_20210910
Version 4.5.4.1800 build_20210923
Version 4.5.4.1892 build_20211223
Version 4.5.4.1931 build_20220128
Version 4.5.4.2012 build_20220419
Version 4.5.4.2117 build_20220802
Version 4.5.4.2280 build_20230112
Version 4.5.4.2374 build_20230416
Version 4.5.4.2467 build_20230718
Version 4.5.4.2627 build_20231225
Configuration B
15 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version h4.5.4.1771 build_20210825
Version h4.5.4.1800 build_20210923
Version h4.5.4.1813 build_20211006
Version h4.5.4.1848 build_20211109
Version h4.5.4.1892 build_20211223
Version h4.5.4.1951 build_20220218
Version h4.5.4.1971 build_20220310
Version h4.5.4.1991 build_20220330
Version h4.5.4.2052 build_20220530
Version h4.5.4.2138 build_20220824
Version h4.5.4.2217 build_20221111
Version h4.5.4.2272 build_20230105
Version h4.5.4.2374 build_20230417
Version h4.5.4.2476 build_20230728
Version h4.5.4.2626 build_20231225

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.