Command Injection Vulnerability in QNAP Operating Systems
CVE-2023-23356

5.5MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
19 December 2024

Summary

CVE-2023-23356 is a critical command injection vulnerability discovered in multiple versions of QNAP's operating system. This vulnerability allows remote attackers, who have obtained administrator-level access, to execute arbitrary commands on the affected devices. Exploiting this weakness could lead to severe consequences, including unauthorized data access and system manipulation. QNAP has addressed this security flaw in QuFirewall version 2.3.3 released on March 27, 2023, and all subsequent updates. Users are strongly advised to update their systems to mitigate risks and enhance security.

Affected Version(s)

QuFirewall 2.3.x < 2.3.3 ( 2023/03/27 )

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kaibro
.