QNAP QTS Vulnerability Affects Multiple Versions, Fix Released
CVE-2023-34974

8.8HIGH

Key Information:

Vendor
QNAP
Status
Vendor
CVE Published:
6 September 2024

Summary

An OS command injection vulnerability has been identified in multiple versions of the QNAP operating system, allowing attackers to execute arbitrary commands through network interfaces. This vulnerability impacts various installations, potentially leading to unauthorized control over affected systems. It is crucial for users to update their software to the specified secure releases to mitigate these risks.

Affected Version(s)

QTS 4.5.x < 4.5.4.2790 build 20240605

QuTS hero h4.5.x

QES 2.2.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

huasheng_mangguo
.