CVE-2023-23367

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QuTS hero h5.0.1.2376 build 20230421 and later
QuTScloud c5.1.0.2498 and later
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
qnapCNA
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
qnapqts
5.0.0.1716:build_20210701
qnapqts
5.0.0.1785:build_20210908
qnapqts
5.0.0.1808:build_20211001
qnapqts
5.0.0.1828:build_20211020
qnapqts
5.0.0.1837:build_20211029
qnapqts
5.0.0.1850:build_20211111
qnapqts
5.0.0.1853:build_20211114
qnapqts
5.0.0.1858:build_20211119
qnapqts
5.0.0.1870:build_20211201
qnapqts
5.0.1.2034:build_20220515
qnapqts
5.0.1.2079:build_20220629
qnapqts
5.0.1.2131:build_20220820
qnapqts
5.0.1.2137:build_20220826
qnapqts
5.0.1.2145:build_20220903
qnapqts
5.0.1.2173:build_20221001
qnapqts
5.0.1.2194:build_20221022
qnapqts
5.0.1.2234:build_20221201
qnapqts
5.0.1.2248:build_20221215
qnapqts
5.0.1.2277:build_20230112
qnapqts
5.0.1.2346:build_20230322
𝑥
= Vulnerable software versions