CVE-2023-34975OS Command Injection in Systems INC QTS

Severity
8.8HIGHNVD
CNA6.6
EPSS
0.1%
top 74.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and later QTS 4.5.4.2627 build 20231225 and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5qnap_systems_inc/quts_heroh4.5.xh4.5.4.2626 build 20231225
CVEListV5qnap_systems_inc/qts4.5.x4.5.4.2627 build 20231225
NVDqnap/video_station< 5.7.0

🔴Vulnerability Details

2
GHSA
GHSA-grxq-cfv6-jw9w: A SQL injection vulnerability has been reported to affect Video Station2023-10-13
CVEList
QTS, QuTS hero, QuTScloud2023-10-13
CVE-2023-34975 — OS Command Injection | cvebase