CVE-2023-34980
EUVD-2023-3901908.03.2024, 17:15
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qnap | qts | 4.5.1 ≤ 𝑥 < 4.5.4.2627 |
| qnap | qts | 4.5.4.2627 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| qnap | qts | 4.5.0 ≤ 𝑥 < 4.5.4.2627_build 20231225 | ADP |
| qnap | quts_hero | h4.5 ≤ 𝑥 < h4.5.4.2626_build 20231225 | ADP |