5.8

CVE-2023-50358

Exploit

QTS, QuTS hero, QuTScloud

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QTS 4.5.4.2627 build 20231225 and later
QTS 4.3.6.2665 build 20240131 and later
QTS 4.3.4.2675 build 20240131 and later
QTS 4.3.3.2644 build 20240131 and later
QTS 4.2.6 build 20240131 and later
QuTS hero h5.1.5.2647 build 20240118 and later
QuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.1.5.2651 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version >= 4.2.0 < 4.2.6
Qnap ≫ Qts Version >= 4.3.0 < 4.3.3.2644
Qnap ≫ Qts Version >= 4.3.4 < 4.3.4.2675
Qnap ≫ Qts Version >= 4.3.5 < 4.3.6.2665
Qnap ≫ Qts Version >= 4.5.1 < 4.5.4.2627
Qnap ≫ Qts Version >= 5.1.0 < 5.1.5.2645
Qnap ≫ Qts Version 4.2.6 Update -
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107
Qnap ≫ Qts Version 4.2.6 Update build_20200109
Qnap ≫ Qts Version 4.2.6 Update build_20200421
Qnap ≫ Qts Version 4.2.6 Update build_20200611
Qnap ≫ Qts Version 4.2.6 Update build_20200821
Qnap ≫ Qts Version 4.2.6 Update build_20210327
Qnap ≫ Qts Version 4.2.6 Update build_20211215
Qnap ≫ Qts Version 4.2.6 Update build_20220304
Qnap ≫ Qts Version 4.2.6 Update build_20220623
Qnap ≫ Qts Version 4.2.6 Update build_20221028
Qnap ≫ Qts Version 4.2.6 Update build_20230621
Qnap ≫ Qts Version 4.5.4.2627 Update -
Qnap ≫ Qts Version 5.1.5.2645 Update -
Qnap ≫ Quts Hero Version >= h4.5.0 < h4.5.4.2626
Qnap ≫ Quts Hero Version >= h5.0.0 < h5.1.5.2647
Qnap ≫ Quts Hero Version h4.5.4.2626 Update -
Qnap ≫ Quts Hero Version h5.1.5.2647 Update -
Qnap ≫ Qutscloud Version >= c5.0.0.1919 < c5.1.5.2651
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.52% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@qnapsecurity.com.tw 5.8 1.6 3.7
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.qnap.com/en/security-advisory/qsa-23-57
Vendor Advisory
https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/
Third Party Advisory
Exploit
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213941-1032
Third Party Advisory