CVE-2023-47565 KEV
8.0
HIGH · CVSS 3.1 · EPSS 73.3% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2024-01-11.
Description
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
Scoring
| CVSS | 8.0 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 73.28% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2024-01-11 |
| Public exploit | none known |
| Published | 2023-12-08 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | QNAP VioStor NVR OS Command Injection Vulnerability |
|---|---|
| Added | 2023-12-21 |
| Due | 2024-01-11 |
| Vendor / product | QNAP / VioStor NVR |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| qnap | qvr firmware |
References
→ the Explorer · watch your stack · NVD