« Volver al listado

CVE-2023-34975

Estado: ModificadaAlta (8.8)—

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected.

We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and later QTS 4.5.4.2627 build 20231225 and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-34975",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTS hero",
          "versions": [
            {
              "status": "affected",
              "version": "h4.5.x",
              "lessThan": "h4.5.4.2626 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QTS",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.x",
              "lessThan": "4.5.4.2627 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTScloud",
          "versions": [
            {
              "status": "unaffected",
              "version": "c5.x.x",
              "lessThan": "4.5.4.2627 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-13T20:15:10.153",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-12",
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-12",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.\nQuTScloud is not affected.\n\nWe have already fixed the vulnerability in the following versions:\nQuTS hero h4.5.4.2626 build 20231225 and later\nQTS 4.5.4.2627 build 20231225 and later"
    },
    {
      "lang": "es",
      "value": "Se ha informado que una vulnerabilidad de inyección SQL afecta a Video Station. Si se explota, la vulnerabilidad podría permitir a los usuarios autenticados inyectar código malicioso a través de una red. Ya se ha solucionado la vulnerabilidad en la siguiente versión: Video Station 5.7.0 (2023/07/27) y posteriores"
    }
  ],
  "lastModified": "2026-06-17T06:04:12.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41493329-139C-4B96-9C16-19DCF1698ACC",
              "versionEndExcluding": "5.7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}