← back
CVE-2023-23368criticalCWE-78

QTS, QuTS hero, QuTScloud

33Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 19%
exploitation probability
19%top 3% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in QNAP operating systems allows attackers to run unauthorized commands on affected devices over a network. This is a critical vulnerability that could give attackers complete control of the system.

Technical detail

OS command injection vulnerability (CWE-78) in QTS, QuTS hero, and QuTScloud that permits unauthenticated remote command execution via network vectors. The vulnerability affects multiple OS versions prior to specified patched builds; exploitation results in arbitrary code execution with system privileges.

Summary generated and translated by AI from the official description.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTS hero h4.5.4.2374 build 20230417 and later QuTScloud c5.0.1.2374 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H