7.2

CVE-2023-23367

QTS, QuTS hero, QuTScloud

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QuTS hero h5.0.1.2376 build 20230421 and later
QuTScloud c5.1.0.2498 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.0.0.1716 Update build_20210701
Qnap ≫ Qts Version 5.0.0.1785 Update build_20210908
Qnap ≫ Qts Version 5.0.0.1808 Update build_20211001
Qnap ≫ Qts Version 5.0.0.1828 Update build_20211020
Qnap ≫ Qts Version 5.0.0.1837 Update build_20211029
Qnap ≫ Qts Version 5.0.0.1850 Update build_20211111
Qnap ≫ Qts Version 5.0.0.1853 Update build_20211114
Qnap ≫ Qts Version 5.0.0.1858 Update build_20211119
Qnap ≫ Qts Version 5.0.0.1870 Update build_20211201
Qnap ≫ Qts Version 5.0.1.2034 Update build_20220515
Qnap ≫ Qts Version 5.0.1.2079 Update build_20220629
Qnap ≫ Qts Version 5.0.1.2131 Update build_20220820
Qnap ≫ Qts Version 5.0.1.2137 Update build_20220826
Qnap ≫ Qts Version 5.0.1.2145 Update build_20220903
Qnap ≫ Qts Version 5.0.1.2173 Update build_20221001
Qnap ≫ Qts Version 5.0.1.2194 Update build_20221022
Qnap ≫ Qts Version 5.0.1.2234 Update build_20221201
Qnap ≫ Qts Version 5.0.1.2248 Update build_20221215
Qnap ≫ Qts Version 5.0.1.2277 Update build_20230112
Qnap ≫ Qts Version 5.0.1.2346 Update build_20230322
Qnap ≫ Quts Hero Version h5.0.0.1772 Update build_20210826
Qnap ≫ Quts Hero Version h5.0.0.1844 Update build_20211105
Qnap ≫ Quts Hero Version h5.0.0.1856 Update build_20211117
Qnap ≫ Quts Hero Version h5.0.0.1892 Update build_20211222
Qnap ≫ Quts Hero Version h5.0.0.1900 Update build_20211228
Qnap ≫ Quts Hero Version h5.0.0.1949 Update build_20220215
Qnap ≫ Quts Hero Version h5.0.0.1986 Update build_20220324
Qnap ≫ Quts Hero Version h5.0.0.2022 Update build_20220428
Qnap ≫ Quts Hero Version h5.0.0.2069 Update build_20220614
Qnap ≫ Quts Hero Version h5.0.0.2120 Update build_20220804
Qnap ≫ Quts Hero Version h5.0.1.2045 Update build_20220526
Qnap ≫ Quts Hero Version h5.0.1.2192 Update build_20221020
Qnap ≫ Quts Hero Version h5.0.1.2248 Update build_20221215
Qnap ≫ Quts Hero Version h5.0.1.2269 Update build_20230104
Qnap ≫ Quts Hero Version h5.0.1.2277 Update build_20230112
Qnap ≫ Quts Hero Version h5.0.1.2348 Update build_20230324
Qnap ≫ Qutscloud Version c5.0.0.1919 Update build_20220119
Qnap ≫ Qutscloud Version c5.0.1.1949 Update build_20220218
Qnap ≫ Qutscloud Version c5.0.1.1998 Update build_20220408
Qnap ≫ Qutscloud Version c5.0.1.2044 Update build_20220524
Qnap ≫ Qutscloud Version c5.0.1.2148 Update build_20220905
Qnap ≫ Qutscloud Version c5.0.1.2374 Update build_20230419
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 4.7 1.2 3.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-23-24
Vendor Advisory