CVE-2023-50358

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QTS 4.5.4.2627 build 20231225 and later
QTS 4.3.6.2665 build 20240131 and later
QTS 4.3.4.2675 build 20240131 and later
QTS 4.3.3.2644 build 20240131 and later
QTS 4.2.6 build 20240131 and later
QuTS hero h5.1.5.2647 build 20240118 and later
QuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.1.5.2651 and later
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
qnapCNA
5.8 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
qnapqts
4.2.0 ≤
𝑥
< 4.2.6
qnapqts
4.3.0 ≤
𝑥
< 4.3.3.2644
qnapqts
4.3.4 ≤
𝑥
< 4.3.4.2675
qnapqts
4.3.5 ≤
𝑥
< 4.3.6.2665
qnapqts
4.5.1 ≤
𝑥
< 4.5.4.2627
qnapqts
5.1.0 ≤
𝑥
< 5.1.5.2645
qnapqts
4.2.6
qnapqts
4.2.6:build_20170517
qnapqts
4.2.6:build_20190322
qnapqts
4.2.6:build_20190730
qnapqts
4.2.6:build_20190921
qnapqts
4.2.6:build_20191107
qnapqts
4.2.6:build_20200109
qnapqts
4.2.6:build_20200421
qnapqts
4.2.6:build_20200611
qnapqts
4.2.6:build_20200821
qnapqts
4.2.6:build_20210327
qnapqts
4.2.6:build_20211215
qnapqts
4.2.6:build_20220304
qnapqts
4.2.6:build_20220623
qnapqts
4.2.6:build_20221028
qnapqts
4.2.6:build_20230621
qnapqts
4.5.4.2627
qnapqts
5.1.5.2645
𝑥
= Vulnerable software versions