// For flags

CVE-2023-23362

QTS, QuTS hero, QuTScloud

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices.

We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QTS 4.5.4.2374 build 20230416 and later
QuTS hero h5.0.1.2376 build 20230421 and later
QuTS hero h4.5.4.2374 build 20230417 and later
QuTScloud c5.0.1.2374 and later

Se ha informado que una vulnerabilidad de inyección de comandos del Sistema Operativo afecta a los sistemas operativos de QNAP. Si se explota, la vulnerabilidad permite a usuarios remotos autenticados ejecutar comandos a través de dispositivos QNAP susceptibles. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 5.0.1.2376 compilación 20230421 y posteriores QTS 4.5.4.2374 compilación 20230416 y posteriores QuTS hero h5.0.1.2376 compilación 20230421 y posteriores QuTS hero h4.5.4.2374 compilación 20230417 y posteriores QuTScloud c5.0.1.2374 y posteriores

*Credits: YC of the M1QLin security team
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-11 CVE Reserved
  • 2023-09-22 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
  • CAPEC-15: Command Delimiters
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.5.4 < 4.5.4.2374
Search vendor "Qnap" for product "Qts" and version " >= 4.5.4 < 4.5.4.2374"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 5.0.1 < 5.0.1.2376
Search vendor "Qnap" for product "Qts" and version " >= 5.0.1 < 5.0.1.2376"
-
Affected
Qnap
Search vendor "Qnap"
Quts Hero
Search vendor "Qnap" for product "Quts Hero"
>= h4.5.4 < h4.5.4.2374
Search vendor "Qnap" for product "Quts Hero" and version " >= h4.5.4 < h4.5.4.2374"
-
Affected
Qnap
Search vendor "Qnap"
Quts Hero
Search vendor "Qnap" for product "Quts Hero"
>= h5.0.1 < h5.0.1.2376
Search vendor "Qnap" for product "Quts Hero" and version " >= h5.0.1 < h5.0.1.2376"
-
Affected
Qnap
Search vendor "Qnap"
Qutscloud
Search vendor "Qnap" for product "Qutscloud"
>= c5.0.1 <= c5.0.1.2374
Search vendor "Qnap" for product "Qutscloud" and version " >= c5.0.1 <= c5.0.1.2374"
-
Affected