« Volver al listado

CVE-2023-34974

Estado: AnalizadaAlta (8.8)—

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. QuTScloud, QVR, QES are not affected.

We have already fixed the vulnerability in the following versions: QTS 4.5.4.2790 build 20240605 and later QuTS hero h4.5.4.2626 build 20231225 and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-34974",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-34974",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-06T17:22:28.665908Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QTS",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.x",
              "lessThan": "4.5.4.2790 build 20240605",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTS hero",
          "versions": [
            {
              "status": "affected",
              "version": "h4.5.x",
              "lessThan": "h4.5.4.2626 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTScloud",
          "versions": [
            {
              "status": "unaffected",
              "version": "c5.x.x"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QVR",
          "versions": [
            {
              "status": "unaffected",
              "version": "5.1.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QES",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.2.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*"
          ],
          "vendor": "qnap",
          "product": "qts",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.4.2790_build_20240605",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*"
          ],
          "vendor": "qnap",
          "product": "quts_hero",
          "versions": [
            {
              "status": "affected",
              "version": "h4.5.0",
              "lessThan": "h4.5.4.2626_build_20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-06T17:15:11.440",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-32",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.\nQuTScloud, QVR, QES are not affected.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 4.5.4.2790 build 20240605 and later\nQuTS hero h4.5.4.2626 build 20231225 and later"
    },
    {
      "lang": "es",
      "value": "Se ha informado de una vulnerabilidad de inyección de comandos del sistema operativo que afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los usuarios ejecutar comandos a través de una red. QuTScloud, QVR y QES no se ven afectados. Ya hemos corregido la vulnerabilidad en las siguientes versiones: QTS 4.5.4.2790, compilación 20240605 y posteriores QuTS hero h4.5.4.2626, compilación 20231225 y posteriores"
    }
  ],
  "lastModified": "2026-06-17T06:04:11.870",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1715:build_20210630:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AA3560E-1778-4278-AD5A-6EB3A63A39A5"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1723:build_20210708:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39E9AF51-0254-472F-B31F-6ADF1848CBD6"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1741:build_20210726:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBB29CD6-B6BC-4C3E-AD44-8D822D10093C"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1787:build_20210910:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7B98F82-9246-496F-8B15-6F320F8E921F"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1800:build_20210923:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE7D1FD6-7D8D-4884-AE7B-5C0BC4E39F69"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1892:build_20211223:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1692CA79-1C6D-4BF8-B49E-3539FCE3E165"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.1931:build_20220128:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C15A236A-4C43-4489-B6F3-EBC9AD786F77"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2012:build_20220419:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECE79BCD-8F86-46B1-A3C1-AC503DE1876F"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2117:build_20220802:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8303B319-7EA7-42BC-9246-6EBF81DE4545"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2280:build_20230112:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E0F4CCC-F4A5-407D-BA2E-2BBCBA6B731A"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2374:build_20230416:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D3AE695-CEEB-4A0C-A751-9172781B776B"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2467:build_20230718:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69823B98-D875-441C-B89E-DE953665664A"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2627:build_20231225:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D0205D7-12D2-428C-87D7-45F19A61ED7B"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1771:build_20210825:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33191D83-16FB-4BEF-B258-3F04D4D8EC34"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1800:build_20210923:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05EDD381-FF86-4B19-9A9C-F51BED7CEEED"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1813:build_20211006:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C597C878-A1CC-4DBA-A96D-5D8913FE54B6"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1848:build_20211109:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1C66970-8744-4BA1-88EB-2A03F6173327"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1892:build_20211223:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "027242F0-EA9B-494B-A235-046C8BF530F7"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1951:build_20220218:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFB8B2FE-F13C-4CBB-9137-774DB0117194"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1971:build_20220310:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77997210-DB56-40A8-88E3-3615E7DB9006"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.1991:build_20220330:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E441AE07-7D88-4D81-ADCC-0E3AE235C72D"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2052:build_20220530:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68F95726-3CBB-44DD-8247-D766F5A0EA32"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2138:build_20220824:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F901CE2F-AFB9-4616-AB32-481FDD59FD09"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2217:build_20221111:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA3E6F9F-1EDC-4E87-B9A3-6031320D2049"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2272:build_20230105:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBFB4927-6E24-4B96-A26B-7F08E34EACA9"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2374:build_20230417:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A294F4D1-A15A-4F57-BA54-6612D816B4C3"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2476:build_20230728:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A198FFCF-F0EC-4145-8A93-021C21EB46D0"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:build_20231225:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76DB09FF-7C10-4EDA-A597-A1CDA5ED2BA2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}