Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2023-23369

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia Console 1.4.8 ( 2023/05/05 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later QTS 4.3.4.2451 build 20230621 and later QTS 4.3.3.2420 build 20230621 and later QTS 4.2.6 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later

  • Published: Nov 3, 2023
  • Updated: Nov 16, 2023
  • CVE: CVE-2023-23369
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Software From Fixed in
qnap / qts 5.1.0.2348-build_20230325 5.1.0.2348-build_20230325.x
qnap / qts 4.3.6.1831-build_20211019 4.3.6.1831-build_20211019.x
qnap / qts 4.3.6.1750-build_20210730 4.3.6.1750-build_20210730.x
qnap / qts 4.3.6.1711-build_20210621 4.3.6.1711-build_20210621.x
qnap / qts 4.3.6.1663-build_20210504 4.3.6.1663-build_20210504.x
qnap / qts 4.3.6.2050-build_20220526 4.3.6.2050-build_20220526.x
qnap / qts 4.3.6.1965-build_20220302 4.3.6.1965-build_20220302.x
qnap / qts 4.3.6.1907-build_20220103 4.3.6.1907-build_20220103.x
qnap / qts 4.3.6.2232-build_20221124 4.3.6.2232-build_20221124.x
qnap / qts 4.3.6.1620-build_20210322 4.3.6.1620-build_20210322.x
qnap / qts 4.3.6.1446-build_20200929 4.3.6.1446-build_20200929.x
qnap / qts 4.3.6.1411-build_20200825 4.3.6.1411-build_20200825.x
qnap / qts 4.3.6.1333-build_20200608 4.3.6.1333-build_20200608.x
qnap / qts 4.3.6.1286-build_20200422 4.3.6.1286-build_20200422.x
qnap / qts 4.3.6.1263-build_20200330 4.3.6.1263-build_20200330.x
qnap / qts 4.3.6.1218-build_20200214 4.3.6.1218-build_20200214.x
qnap / qts 4.3.6.1154-build_20191212 4.3.6.1154-build_20191212.x
qnap / qts 4.3.6.1070-build_20190919 4.3.6.1070-build_20190919.x
qnap / qts 4.3.6.1033-build_20190813 4.3.6.1033-build_20190813.x
qnap / qts 4.3.6.1013-build_20190724 4.3.6.1013-build_20190724.x
qnap / qts 4.3.6.0993-build_20190704 4.3.6.0993-build_20190704.x
qnap / qts 4.3.6.0979-build_20190620 4.3.6.0979-build_20190620.x
qnap / qts 4.3.6.0959-build_20190531 4.3.6.0959-build_20190531.x
qnap / qts 4.3.6.0944-build_20190516 4.3.6.0944-build_20190516.x
qnap / qts 4.3.6.0923-build_20190425 4.3.6.0923-build_20190425.x
qnap / qts 4.3.6.0907-build_20190409 4.3.6.0907-build_20190409.x
qnap / qts 4.3.6.0895-build_20190328 4.3.6.0895-build_20190328.x
qnap / qts 4.3.4.2242-build_20221124 4.3.4.2242-build_20221124.x
qnap / qts 4.3.4.2107-build_20220712 4.3.4.2107-build_20220712.x
qnap / qts 4.3.4.1976-build_20220303 4.3.4.1976-build_20220303.x
qnap / qts 4.3.4.1652-build_20210413 4.3.4.1652-build_20210413.x
qnap / qts 4.3.4.1632-build_20210324 4.3.4.1632-build_20210324.x
qnap / qts 4.3.4.1463-build_20201006 4.3.4.1463-build_20201006.x
qnap / qts 4.3.4.1417-build_20200821 4.3.4.1417-build_20200821.x
qnap / qts 4.3.4.1368-build_20200703 4.3.4.1368-build_20200703.x
qnap / qts 4.3.4.1282-build_20200408 4.3.4.1282-build_20200408.x
qnap / qts 4.3.4.1190-build_20200107 4.3.4.1190-build_20200107.x
qnap / qts 4.3.4.1082-build_20190921 4.3.4.1082-build_20190921.x
qnap / qts 4.3.4.1029-build_20190730 4.3.4.1029-build_20190730.x
qnap / qts 4.3.4.0899-build_20190322 4.3.4.0899-build_20190322.x
qnap / qts 4.3.3.2211-build_20221124 4.3.3.2211-build_20221124.x
qnap / qts 4.3.3.2057-build_20220623 4.3.3.2057-build_20220623.x
qnap / qts 4.3.3.1945-build_20220303 4.3.3.1945-build_20220303.x
qnap / qts 4.3.3.1864-build_20211212 4.3.3.1864-build_20211212.x
qnap / qts 4.3.3.1799-build_20211008 4.3.3.1799-build_20211008.x
qnap / qts 4.3.3.1693-build_20210624 4.3.3.1693-build_20210624.x
qnap / qts 4.3.3.1677-build_20210608 4.3.3.1677-build_20210608.x
qnap / qts 4.3.3.1624-build_20210416 4.3.3.1624-build_20210416.x
qnap / qts 4.3.3.1432-build_20201006 4.3.3.1432-build_20201006.x
qnap / qts 4.3.3.1386-build_20200821 4.3.3.1386-build_20200821.x
qnap / qts 4.3.3.1315-build_20200611 4.3.3.1315-build_20200611.x
qnap / qts 4.3.3.1252-build_20200409 4.3.3.1252-build_20200409.x
qnap / qts 4.3.3.1161-build_20200109 4.3.3.1161-build_20200109.x
qnap / qts 4.3.3.1098-build_20191107 4.3.3.1098-build_20191107.x
qnap / qts 4.3.3.1051-build_20190921 4.3.3.1051-build_20190921.x
qnap / qts 4.3.3.0998-build_20190730 4.3.3.0998-build_20190730.x
qnap / qts 4.3.3.0868-build_20190322 4.3.3.0868-build_20190322.x
qnap / qts 4.3.3.0174-build_20170503 4.3.3.0174-build_20170503.x
qnap / qts 4.2.6-build_20170517 4.2.6-build_20170517.x
qnap / qts 4.2.6-build_20190322 4.2.6-build_20190322.x
qnap / qts 4.2.6-build_20190730 4.2.6-build_20190730.x
qnap / qts 4.2.6-build_20190921 4.2.6-build_20190921.x
qnap / qts 4.2.6-build_20191107 4.2.6-build_20191107.x
qnap / qts 4.2.6-build_20200109 4.2.6-build_20200109.x
qnap / qts 4.2.6-build_20200421 4.2.6-build_20200421.x
qnap / qts 4.2.6-build_20200611 4.2.6-build_20200611.x
qnap / qts 4.2.6-build_20200821 4.2.6-build_20200821.x
qnap / qts 4.2.6-build_20210327 4.2.6-build_20210327.x
qnap / qts 4.2.6-build_20211215 4.2.6-build_20211215.x
qnap / qts 4.2.6-build_20221028 4.2.6-build_20221028.x
qnap / qts 4.2.6-build_20220623 4.2.6-build_20220623.x
qnap / qts 4.2.6-build_20220304 4.2.6-build_20220304.x
qnap / multimedia_console 2.1.1 2.1.1.x
qnap / multimedia_console 2.1.0 2.1.0.x
qnap / multimedia_console 1.4.7 1.4.7.x
qnap / multimedia_console 1.4.6 1.4.6.x
qnap / multimedia_console 1.4.5 1.4.5.x
qnap / multimedia_console 1.4.4 1.4.4.x
qnap / multimedia_console 1.4.3 1.4.3.x
qnap / media_streaming_add-on 500.1.1.1 500.1.1.1.x
qnap / media_streaming_add-on 500.1.1.0 500.1.1.0.x
qnap / media_streaming_add-on 500.0.0.10 500.0.0.10.x
qnap / media_streaming_add-on 500.0.0.9 500.0.0.9.x
qnap / media_streaming_add-on 500.0.0.8 500.0.0.8.x
qnap / media_streaming_add-on 500.0.0.7 500.0.0.7.x
qnap / media_streaming_add-on 500.0.0.6 500.0.0.6.x
qnap / media_streaming_add-on 500.0.0.5 500.0.0.5.x
qnap / media_streaming_add-on 500.0.0.4 500.0.0.4.x
qnap / media_streaming_add-on 500.0.0.3 500.0.0.3.x
qnap / media_streaming_add-on 500.0.0.1 500.0.0.1.x
qnap / media_streaming_add-on 500.0.0.0 500.0.0.0.x