CVE-2023-23368
03.11.2023, 17:15
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and later
| Vendor | Product | Version |
|---|---|---|
| qnap | qts | 5.0.1 |
| qnap | qts | 5.0.1.2034:build_20220515 |
| qnap | qts | 5.0.1.2079:build_20220629 |
| qnap | qts | 5.0.1.2131:build_20220820 |
| qnap | qts | 5.0.1.2137:build_20220826 |
| qnap | qts | 5.0.1.2145:build_20220903 |
| qnap | qts | 5.0.1.2173:build_20221001 |
| qnap | qts | 5.0.1.2194:build_20221022 |
| qnap | qts | 5.0.1.2234:build_20221201 |
| qnap | qts | 5.0.1.2248:build_20221215 |
| qnap | qts | 5.0.1.2277:build_20230112 |
| qnap | qts | 5.0.1.2346:build_20230322 |
| qnap | qts | 4.5.4 |
| qnap | qts | 4.5.4.1715:build_20210630 |
| qnap | qts | 4.5.4.1723:build_20210708 |
| qnap | qts | 4.5.4.1741:build_20210726 |
| qnap | qts | 4.5.4.1787:build_20210910 |
| qnap | qts | 4.5.4.1800:build_20210923 |
| qnap | qts | 4.5.4.1892:build_20211223 |
| qnap | qts | 4.5.4.1931:build_20220128 |
| qnap | qts | 4.5.4.2012:build_20220419 |
| qnap | qts | 4.5.4.2117:build_20220802 |
| qnap | qts | 4.5.4.2280:build_20230112 |
𝑥
= Vulnerable software versions