9.8

CVE-2023-23368

QTS, QuTS hero, QuTScloud

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QTS 4.5.4.2374 build 20230416 and later
QuTS hero h5.0.1.2376 build 20230421 and later
QuTS hero h4.5.4.2374 build 20230417 and later
QuTScloud c5.0.1.2374 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.0.1 Update -
Qnap ≫ Qts Version 5.0.1.2034 Update build_20220515
Qnap ≫ Qts Version 5.0.1.2079 Update build_20220629
Qnap ≫ Qts Version 5.0.1.2131 Update build_20220820
Qnap ≫ Qts Version 5.0.1.2137 Update build_20220826
Qnap ≫ Qts Version 5.0.1.2145 Update build_20220903
Qnap ≫ Qts Version 5.0.1.2173 Update build_20221001
Qnap ≫ Qts Version 5.0.1.2194 Update build_20221022
Qnap ≫ Qts Version 5.0.1.2234 Update build_20221201
Qnap ≫ Qts Version 5.0.1.2248 Update build_20221215
Qnap ≫ Qts Version 5.0.1.2277 Update build_20230112
Qnap ≫ Qts Version 5.0.1.2346 Update build_20230322
Qnap ≫ Qts Version 4.5.4 Update -
Qnap ≫ Qts Version 4.5.4.1715 Update build_20210630
Qnap ≫ Qts Version 4.5.4.1723 Update build_20210708
Qnap ≫ Qts Version 4.5.4.1741 Update build_20210726
Qnap ≫ Qts Version 4.5.4.1787 Update build_20210910
Qnap ≫ Qts Version 4.5.4.1800 Update build_20210923
Qnap ≫ Qts Version 4.5.4.1892 Update build_20211223
Qnap ≫ Qts Version 4.5.4.1931 Update build_20220128
Qnap ≫ Qts Version 4.5.4.2012 Update build_20220419
Qnap ≫ Qts Version 4.5.4.2117 Update build_20220802
Qnap ≫ Qts Version 4.5.4.2280 Update build_20230112
Qnap ≫ Quts Hero Version h5.0.1.2045 Update build_20220526
Qnap ≫ Quts Hero Version h5.0.1.2192 Update build_20221020
Qnap ≫ Quts Hero Version h5.0.1.2248 Update build_20221215
Qnap ≫ Quts Hero Version h5.0.1.2269 Update build_20230104
Qnap ≫ Quts Hero Version h5.0.1.2277 Update build_20230112
Qnap ≫ Quts Hero Version h5.0.1.2348 Update build_20230324
Qnap ≫ Quts Hero Version h4.5.4.1771 Update build_20210825
Qnap ≫ Quts Hero Version h4.5.4.1800 Update build_20210923
Qnap ≫ Quts Hero Version h4.5.4.1813 Update build_20211006
Qnap ≫ Quts Hero Version h4.5.4.1848 Update build_20211109
Qnap ≫ Quts Hero Version h4.5.4.1892 Update build_20211223
Qnap ≫ Quts Hero Version h4.5.4.1951 Update build_20220218
Qnap ≫ Quts Hero Version h4.5.4.1971 Update build_20220310
Qnap ≫ Quts Hero Version h4.5.4.1991 Update build_20220330
Qnap ≫ Quts Hero Version h4.5.4.2052 Update build_20220530
Qnap ≫ Quts Hero Version h4.5.4.2138 Update build_20220824
Qnap ≫ Quts Hero Version h4.5.4.2217 Update build_20221111
Qnap ≫ Quts Hero Version h4.5.4.2272 Update build_20230105
Qnap ≫ Qutscloud Version c5.0.1.1949 Update build_20220218
Qnap ≫ Qutscloud Version c5.0.1.1998 Update build_20220408
Qnap ≫ Qutscloud Version c5.0.1.2044 Update build_20220524
Qnap ≫ Qutscloud Version c5.0.1.2148 Update build_20220905
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.83% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-23-31
Vendor Advisory