CVE-2023-23367
10.11.2023, 15:15
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTScloud c5.1.0.2498 and later
Vendor | Product | Version |
---|---|---|
qnap | qts | 5.0.0.1716:build_20210701 |
qnap | qts | 5.0.0.1785:build_20210908 |
qnap | qts | 5.0.0.1808:build_20211001 |
qnap | qts | 5.0.0.1828:build_20211020 |
qnap | qts | 5.0.0.1837:build_20211029 |
qnap | qts | 5.0.0.1850:build_20211111 |
qnap | qts | 5.0.0.1853:build_20211114 |
qnap | qts | 5.0.0.1858:build_20211119 |
qnap | qts | 5.0.0.1870:build_20211201 |
qnap | qts | 5.0.1.2034:build_20220515 |
qnap | qts | 5.0.1.2079:build_20220629 |
qnap | qts | 5.0.1.2131:build_20220820 |
qnap | qts | 5.0.1.2137:build_20220826 |
qnap | qts | 5.0.1.2145:build_20220903 |
qnap | qts | 5.0.1.2173:build_20221001 |
qnap | qts | 5.0.1.2194:build_20221022 |
qnap | qts | 5.0.1.2234:build_20221201 |
qnap | qts | 5.0.1.2248:build_20221215 |
qnap | qts | 5.0.1.2277:build_20230112 |
qnap | qts | 5.0.1.2346:build_20230322 |
𝑥
= Vulnerable software versions