QNAP QTS Vulnerability Affects Multiple Versions, Fix Released
CVE-2023-34974
8.8HIGH
Summary
An OS command injection vulnerability has been identified in multiple versions of the QNAP operating system, allowing attackers to execute arbitrary commands through network interfaces. This vulnerability impacts various installations, potentially leading to unauthorized control over affected systems. It is crucial for users to update their software to the specified secure releases to mitigate these risks.
Affected Version(s)
QTS 4.5.x < 4.5.4.2790 build 20240605
QuTS hero h4.5.x
QES 2.2.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
huasheng_mangguo