peter bassill · operator
$ cve CVE-2023-23369 JSON

CVE-2023-23369

9.0
CRITICAL · CVSS 3.1 · EPSS 14.5% (pctl 97)

Patch early

EPSS 14.5% — above the 10% action threshold.

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia Console 1.4.8 ( 2023/05/05 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS14.52% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2023-11-03
Last modified2026-06-17

Affected (3)

VendorProduct
qnapmedia streaming add-on
qnapmultimedia console
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD