« Volver al listado

CVE-2023-34980

Estado: AnalizadaAlta (8.4)—

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following versions: QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-34980",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-34980",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-12T18:15:12.889402Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 1.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QTS",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.x",
              "lessThan": "4.5.4.2627 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuTS hero",
          "versions": [
            {
              "status": "affected",
              "version": "h4.5.x",
              "lessThan": "h4.5.4.2626 build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*"
          ],
          "vendor": "qnap",
          "product": "qts",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.4.2627_build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*"
          ],
          "vendor": "qnap",
          "product": "quts_hero",
          "versions": [
            {
              "status": "affected",
              "version": "h4.5",
              "lessThan": "h4.5.4.2626_build 20231225",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-08T17:15:22.117",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-12",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-24-12",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 4.5.4.2627 build 20231225 and later\nQuTS hero h4.5.4.2626 build 20231225 and later\n"
    },
    {
      "lang": "es",
      "value": "Se ha informado que una vulnerabilidad de inyección de comandos del sistema operativo afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podría permitir a los administradores autenticados ejecutar comandos a través de una red. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 4.5.4.2627 compilación 20231225 y posteriores QuTS hero h4.5.4.2626 compilación 20231225 y posteriores"
    }
  ],
  "lastModified": "2026-06-17T06:04:12.530",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E634DC87-6347-4CB8-8C61-E5E47F56CA13",
              "versionEndExcluding": "4.5.4.2627",
              "versionStartIncluding": "4.5.1"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "320AEB7E-E07B-42AE-8F71-795A516BA5EA"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B689688-0791-4DD8-930C-45AD2AFBCC70",
              "versionEndExcluding": "h4.5.4.2626",
              "versionStartIncluding": "h4.5.0"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CFA8519-D4C0-4ADC-A06B-7694943B06E7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}