A vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated administrators to execute arbitrary commands via susceptible QNAP devices. The vulnerability affects the following QNAP operating systems:
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR
QES is not affected.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2346 build 20230322 and later
QuTS hero h5.0.1.2348 build 20230324 and later
QuTS hero h4.5.4.2374 build 20230417 and later
References
Link | Resource |
---|---|
https://www.qnap.com/en/security-advisory/qsa-23-10 | Vendor Advisory |
https://www.qnap.com/en/security-advisory/qsa-23-10 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
21 Nov 2024, 07:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.qnap.com/en/security-advisory/qsa-23-10 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.6 |
20 Apr 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.qnap.com/en/security-advisory/qsa-23-10 - Vendor Advisory | |
CWE | CWE-77 | |
CPE | cpe:2.3:o:qnap:qvp-41a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qutscloud:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-85a_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-63b:-:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-85b:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-63b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-85a:-:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-41b:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-41b_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-21a:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-63a_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-41a:-:*:*:*:*:*:*:* cpe:2.3:a:qnap:qvr:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* cpe:2.3:h:qnap:qvp-63a:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-85b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qnap:qvp-21a_firmware:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
Summary | A vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated administrators to execute arbitrary commands via susceptible QNAP devices. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVR QES is not affected. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later QuTS hero h4.5.4.2374 build 20230417 and later |
29 Mar 2023, 07:29
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-29 05:15
Updated : 2024-11-21 07:46
NVD link : CVE-2023-23355
Mitre link : CVE-2023-23355
CVE.ORG link : CVE-2023-23355
JSON object : View
Products Affected
qnap
- qvp-41a
- qvr
- qvp-63a_firmware
- qvp-41b_firmware
- qvp-41b
- qvp-21a_firmware
- qvp-41a_firmware
- quts_hero
- qts
- qvp-85b_firmware
- qutscloud
- qvp-63b
- qvp-85a
- qvp-85a_firmware
- qvp-21a
- qvp-85b
- qvp-63a
- qvp-63b_firmware