9.8

CVE-2023-23369

QTS, Multimedia Console, and Media Streaming add-on

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.2 ( 2023/05/04 ) and later
Multimedia Console 1.4.8 ( 2023/05/05 ) and later
QTS 5.1.0.2399 build 20230515 and later
QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.4.2451 build 20230621 and later
QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.6 build 20230621 and later
Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later
Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.1.0.2348 Update build_20230325
Qnap ≫ Qts Version 4.3.6.0895 Update build_20190328
Qnap ≫ Qts Version 4.3.6.0907 Update build_20190409
Qnap ≫ Qts Version 4.3.6.0923 Update build_20190425
Qnap ≫ Qts Version 4.3.6.0944 Update build_20190516
Qnap ≫ Qts Version 4.3.6.0959 Update build_20190531
Qnap ≫ Qts Version 4.3.6.0979 Update build_20190620
Qnap ≫ Qts Version 4.3.6.0993 Update build_20190704
Qnap ≫ Qts Version 4.3.6.1013 Update build_20190724
Qnap ≫ Qts Version 4.3.6.1033 Update build_20190813
Qnap ≫ Qts Version 4.3.6.1070 Update build_20190919
Qnap ≫ Qts Version 4.3.6.1154 Update build_20191212
Qnap ≫ Qts Version 4.3.6.1218 Update build_20200214
Qnap ≫ Qts Version 4.3.6.1263 Update build_20200330
Qnap ≫ Qts Version 4.3.6.1286 Update build_20200422
Qnap ≫ Qts Version 4.3.6.1333 Update build_20200608
Qnap ≫ Qts Version 4.3.6.1411 Update build_20200825
Qnap ≫ Qts Version 4.3.6.1446 Update build_20200929
Qnap ≫ Qts Version 4.3.6.1620 Update build_20210322
Qnap ≫ Qts Version 4.3.6.1663 Update build_20210504
Qnap ≫ Qts Version 4.3.6.1711 Update build_20210621
Qnap ≫ Qts Version 4.3.6.1750 Update build_20210730
Qnap ≫ Qts Version 4.3.6.1831 Update build_20211019
Qnap ≫ Qts Version 4.3.6.1907 Update build_20220103
Qnap ≫ Qts Version 4.3.6.1965 Update build_20220302
Qnap ≫ Qts Version 4.3.6.2050 Update build_20220526
Qnap ≫ Qts Version 4.3.6.2232 Update build_20221124
Qnap ≫ Qts Version 4.3.4.0899 Update build_20190322
Qnap ≫ Qts Version 4.3.4.1029 Update build_20190730
Qnap ≫ Qts Version 4.3.4.1082 Update build_20190921
Qnap ≫ Qts Version 4.3.4.1190 Update build_20200107
Qnap ≫ Qts Version 4.3.4.1282 Update build_20200408
Qnap ≫ Qts Version 4.3.4.1368 Update build_20200703
Qnap ≫ Qts Version 4.3.4.1417 Update build_20200821
Qnap ≫ Qts Version 4.3.4.1463 Update build_20201006
Qnap ≫ Qts Version 4.3.4.1632 Update build_20210324
Qnap ≫ Qts Version 4.3.4.1652 Update build_20210413
Qnap ≫ Qts Version 4.3.4.1976 Update build_20220303
Qnap ≫ Qts Version 4.3.4.2107 Update build_20220712
Qnap ≫ Qts Version 4.3.4.2242 Update build_20221124
Qnap ≫ Qts Version 4.3.3.0174 Update build_20170503
Qnap ≫ Qts Version 4.3.3.0868 Update build_20190322
Qnap ≫ Qts Version 4.3.3.0998 Update build_20190730
Qnap ≫ Qts Version 4.3.3.1051 Update build_20190921
Qnap ≫ Qts Version 4.3.3.1098 Update build_20191107
Qnap ≫ Qts Version 4.3.3.1161 Update build_20200109
Qnap ≫ Qts Version 4.3.3.1252 Update build_20200409
Qnap ≫ Qts Version 4.3.3.1315 Update build_20200611
Qnap ≫ Qts Version 4.3.3.1386 Update build_20200821
Qnap ≫ Qts Version 4.3.3.1432 Update build_20201006
Qnap ≫ Qts Version 4.3.3.1624 Update build_20210416
Qnap ≫ Qts Version 4.3.3.1677 Update build_20210608
Qnap ≫ Qts Version 4.3.3.1693 Update build_20210624
Qnap ≫ Qts Version 4.3.3.1799 Update build_20211008
Qnap ≫ Qts Version 4.3.3.1864 Update build_20211212
Qnap ≫ Qts Version 4.3.3.1945 Update build_20220303
Qnap ≫ Qts Version 4.3.3.2057 Update build_20220623
Qnap ≫ Qts Version 4.3.3.2211 Update build_20221124
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107
Qnap ≫ Qts Version 4.2.6 Update build_20200109
Qnap ≫ Qts Version 4.2.6 Update build_20200421
Qnap ≫ Qts Version 4.2.6 Update build_20200611
Qnap ≫ Qts Version 4.2.6 Update build_20200821
Qnap ≫ Qts Version 4.2.6 Update build_20210327
Qnap ≫ Qts Version 4.2.6 Update build_20211215
Qnap ≫ Qts Version 4.2.6 Update build_20220304
Qnap ≫ Qts Version 4.2.6 Update build_20220623
Qnap ≫ Qts Version 4.2.6 Update build_20221028
Qnap ≫ Multimedia Console Version 2.1.0
Qnap ≫ Multimedia Console Version 2.1.1
Qnap ≫ Multimedia Console Version 1.4.3
Qnap ≫ Multimedia Console Version 1.4.4
Qnap ≫ Multimedia Console Version 1.4.5
Qnap ≫ Multimedia Console Version 1.4.6
Qnap ≫ Multimedia Console Version 1.4.7
Qnap ≫ Media Streaming Add-on Version 500.1.1.0
Qnap ≫ Media Streaming Add-on Version 500.1.1.1
Qnap ≫ Media Streaming Add-on Version 500.0.0.0
Qnap ≫ Media Streaming Add-on Version 500.0.0.1
Qnap ≫ Media Streaming Add-on Version 500.0.0.3
Qnap ≫ Media Streaming Add-on Version 500.0.0.4
Qnap ≫ Media Streaming Add-on Version 500.0.0.5
Qnap ≫ Media Streaming Add-on Version 500.0.0.6
Qnap ≫ Media Streaming Add-on Version 500.0.0.7
Qnap ≫ Media Streaming Add-on Version 500.0.0.8
Qnap ≫ Media Streaming Add-on Version 500.0.0.9
Qnap ≫ Media Streaming Add-on Version 500.0.0.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.52% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-23-35
Vendor Advisory