Description
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-23-54 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-04T19:53:30.491Z
Reserved: 2023-07-27T06:46:01.475Z
Link: CVE-2023-39294
Updated: 2024-08-02T18:02:06.831Z
Status : Modified
Published: 2024-01-05T17:15:08.827
Modified: 2024-11-21T08:15:05.667
Link: CVE-2023-39294
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD