← All CVEs

CVE-2023-23368

critical · 9.8

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and later

9.8
CVSS
18.8%
EPSS (exploit prob.)
97th
EPSS percentile
2023-11-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
qnapqts5.0.1
qnapqts5.0.1.2034
qnapqts5.0.1.2079
qnapqts5.0.1.2131
qnapqts5.0.1.2137
qnapqts5.0.1.2145
qnapqts5.0.1.2173
qnapqts5.0.1.2194
qnapqts5.0.1.2234
qnapqts5.0.1.2248
qnapqts5.0.1.2277
qnapqts5.0.1.2346
qnapqts4.5.4
qnapqts4.5.4.1715
qnapqts4.5.4.1723
qnapqts4.5.4.1741
qnapqts4.5.4.1787
qnapqts4.5.4.1800
qnapqts4.5.4.1892
qnapqts4.5.4.1931
qnapqts4.5.4.2012
qnapqts4.5.4.2117
qnapqts4.5.4.2280
qnapquts_heroh5.0.1.2045
qnapquts_heroh5.0.1.2192
qnapquts_heroh5.0.1.2248
qnapquts_heroh5.0.1.2269
qnapquts_heroh5.0.1.2277
qnapquts_heroh5.0.1.2348
qnapquts_heroh4.5.4.1771
qnapquts_heroh4.5.4.1800
qnapquts_heroh4.5.4.1813
qnapquts_heroh4.5.4.1848
qnapquts_heroh4.5.4.1892
qnapquts_heroh4.5.4.1951
qnapquts_heroh4.5.4.1971
qnapquts_heroh4.5.4.1991
qnapquts_heroh4.5.4.2052
qnapquts_heroh4.5.4.2138
qnapquts_heroh4.5.4.2217

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-23368