CVE-2023-39300

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 4.3.6.2805 build 20240619 and later
QTS 4.3.4.2814 build 20240618 and later
QTS 4.3.3.2784 build 20240619 and later
QTS 4.2.6 build 20240618 and later
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
qnapCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
qnapqts
4.3.6.0895:build_20190328
qnapqts
4.3.6.0907:build_20190409
qnapqts
4.3.6.0923:build_20190425
qnapqts
4.3.6.0944:build_20190516
qnapqts
4.3.6.0959:build_20190531
qnapqts
4.3.6.0979:build_20190620
qnapqts
4.3.6.0993:build_20190704
qnapqts
4.3.6.1013:build_20190724
qnapqts
4.3.6.1033:build_20190813
qnapqts
4.3.6.1070:build_20190919
qnapqts
4.3.6.1154:build_20191212
qnapqts
4.3.6.1218:build_20200214
qnapqts
4.3.6.1263:build_20200330
qnapqts
4.3.6.1286:build_20200422
qnapqts
4.3.6.1333:build_20200608
qnapqts
4.3.6.1411:build_20200825
qnapqts
4.3.6.1446:build_20200929
qnapqts
4.3.6.1620:build_20210322
qnapqts
4.3.6.1663:build_20210504
qnapqts
4.3.6.1711:build_20210621
qnapqts
4.3.6.1750:build_20210730
qnapqts
4.3.6.1831:build_20211019
qnapqts
4.3.6.1907:build_20220103
qnapqts
4.3.6.1965:build_20220302
qnapqts
4.3.6.2050:build_20220526
qnapqts
4.3.6.2232:build_20221124
qnapqts
4.3.6.2441:build_20230621
qnapqts
4.3.6.2665:build_20240131
qnapqts
4.3.4.0899:build_20190322
qnapqts
4.3.4.1029:build_20190730
qnapqts
4.3.4.1082:build_20190921
qnapqts
4.3.4.1190:build_20200107
qnapqts
4.3.4.1282:build_20200408
qnapqts
4.3.4.1368:build_20200703
qnapqts
4.3.4.1417:build_20200821
qnapqts
4.3.4.1463:build_20201006
qnapqts
4.3.4.1632:build_20210324
qnapqts
4.3.4.1652:build_20210413
qnapqts
4.3.4.1976:build_20220303
qnapqts
4.3.4.2107:build_20220712
qnapqts
4.3.4.2242:build_20221124
qnapqts
4.3.4.2451:build_20230621
qnapqts
4.3.4.2675:build_20240131
qnapqts
4.3.3.0174:build_20170503
qnapqts
4.3.3.0868:build_20190322
qnapqts
4.3.3.0998:build_20190730
qnapqts
4.3.3.1051:build_20190921
qnapqts
4.3.3.1098:build_20191107
qnapqts
4.3.3.1161:build_20200109
qnapqts
4.3.3.1252:build_20200409
qnapqts
4.3.3.1315:build_20200611
qnapqts
4.3.3.1386:build_20200821
qnapqts
4.3.3.1432:build_20201006
qnapqts
4.3.3.1624:build_20210416
qnapqts
4.3.3.1677:build_20210608
qnapqts
4.3.3.1693:build_20210624
qnapqts
4.3.3.1799:build_20211008
qnapqts
4.3.3.1864:build_20211212
qnapqts
4.3.3.1945:build_20220303
qnapqts
4.3.3.2057:build_20220623
qnapqts
4.3.3.2211:build_20221124
qnapqts
4.3.3.2420:build_20230621
qnapqts
4.3.3.2644:build_20240131
qnapqts
4.2.6:build_20170517
qnapqts
4.2.6:build_20190322
qnapqts
4.2.6:build_20190730
qnapqts
4.2.6:build_20190921
qnapqts
4.2.6:build_20191107
qnapqts
4.2.6:build_20200109
qnapqts
4.2.6:build_20200421
qnapqts
4.2.6:build_20200611
qnapqts
4.2.6:build_20200821
qnapqts
4.2.6:build_20210327
qnapqts
4.2.6:build_20211215
qnapqts
4.2.6:build_20220304
qnapqts
4.2.6:build_20220623
qnapqts
4.2.6:build_20221028
qnapqts
4.2.6:build_20230621
qnapqts
4.2.6:build_20240131
𝑥
= Vulnerable software versions