← Back

CVE-2023-39300

nvd nist
Published: Sep 6, 2024Modified: Sep 24, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build 20240619 and later QTS 4.3.4.2814 build 20240618 and later QTS 4.3.3.2784 build 20240619 and later QTS 4.2.6 build 20240618 and later

Affected (79)

Products: Qnap: Qts
1 product
Qts
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.6.0895 build_20190328
Version 4.3.6.0907 build_20190409
Version 4.3.6.0923 build_20190425
Version 4.3.6.0944 build_20190516
Version 4.3.6.0959 build_20190531
Version 4.3.6.0979 build_20190620
Version 4.3.6.0993 build_20190704
Version 4.3.6.1013 build_20190724
Version 4.3.6.1033 build_20190813
Version 4.3.6.1070 build_20190919
Version 4.3.6.1154 build_20191212
Version 4.3.6.1218 build_20200214
Version 4.3.6.1263 build_20200330
Version 4.3.6.1286 build_20200422
Version 4.3.6.1333 build_20200608
Version 4.3.6.1411 build_20200825
Version 4.3.6.1446 build_20200929
Version 4.3.6.1620 build_20210322
Version 4.3.6.1663 build_20210504
Version 4.3.6.1711 build_20210621
Version 4.3.6.1750 build_20210730
Version 4.3.6.1831 build_20211019
Version 4.3.6.1907 build_20220103
Version 4.3.6.1965 build_20220302
Version 4.3.6.2050 build_20220526
Version 4.3.6.2232 build_20221124
Version 4.3.6.2441 build_20230621
Version 4.3.6.2665 build_20240131
Configuration B
15 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.4.0899 build_20190322
Version 4.3.4.1029 build_20190730
Version 4.3.4.1082 build_20190921
Version 4.3.4.1190 build_20200107
Version 4.3.4.1282 build_20200408
Version 4.3.4.1368 build_20200703
Version 4.3.4.1417 build_20200821
Version 4.3.4.1463 build_20201006
Version 4.3.4.1632 build_20210324
Version 4.3.4.1652 build_20210413
Version 4.3.4.1976 build_20220303
Version 4.3.4.2107 build_20220712
Version 4.3.4.2242 build_20221124
Version 4.3.4.2451 build_20230621
Version 4.3.4.2675 build_20240131
Configuration C
20 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.3.0174 build_20170503
Version 4.3.3.0868 build_20190322
Version 4.3.3.0998 build_20190730
Version 4.3.3.1051 build_20190921
Version 4.3.3.1098 build_20191107
Version 4.3.3.1161 build_20200109
Version 4.3.3.1252 build_20200409
Version 4.3.3.1315 build_20200611
Version 4.3.3.1386 build_20200821
Version 4.3.3.1432 build_20201006
Version 4.3.3.1624 build_20210416
Version 4.3.3.1677 build_20210608
Version 4.3.3.1693 build_20210624
Version 4.3.3.1799 build_20211008
Version 4.3.3.1864 build_20211212
Version 4.3.3.1945 build_20220303
Version 4.3.3.2057 build_20220623
Version 4.3.3.2211 build_20221124
Version 4.3.3.2420 build_20230621
Version 4.3.3.2644 build_20240131
Configuration D
16 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.2.6 build_20170517
Version 4.2.6 build_20190322
Version 4.2.6 build_20190730
Version 4.2.6 build_20190921
Version 4.2.6 build_20191107
Version 4.2.6 build_20200109
Version 4.2.6 build_20200421
Version 4.2.6 build_20200611
Version 4.2.6 build_20200821
Version 4.2.6 build_20210327
Version 4.2.6 build_20211215
Version 4.2.6 build_20220304
Version 4.2.6 build_20220623
Version 4.2.6 build_20221028
Version 4.2.6 build_20230621
Version 4.2.6 build_20240131

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.