Vulnerability Details CVE-2023-34979
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2790 build 20240605 and later
QuTS hero h4.5.4.2790 build 20240606 and later
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.3%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2023-34979
-
cpe:2.3:o:qnap:qts:4.5.4.1715
-
cpe:2.3:o:qnap:qts:4.5.4.1723
-
cpe:2.3:o:qnap:qts:4.5.4.1741
-
cpe:2.3:o:qnap:qts:4.5.4.1787
-
cpe:2.3:o:qnap:qts:4.5.4.1800
-
cpe:2.3:o:qnap:qts:4.5.4.1892
-
cpe:2.3:o:qnap:qts:4.5.4.1931
-
cpe:2.3:o:qnap:qts:4.5.4.2012
-
cpe:2.3:o:qnap:qts:4.5.4.2117
-
cpe:2.3:o:qnap:qts:4.5.4.2280
-
cpe:2.3:o:qnap:qts:4.5.4.2374
-
cpe:2.3:o:qnap:qts:4.5.4.2467
-
cpe:2.3:o:qnap:qts:4.5.4.2627
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1771
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1800
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1813
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1848
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1892
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1951
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1971
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.1991
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2052
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2138
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2217
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2272
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2374
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2476
-
cpe:2.3:o:qnap:quts_hero:h4.5.4.2626