CVE-2023-23368 is a critical OS command injection vulnerability impacting QNAP QTS, QuTS hero, and QuTScloud operating systems. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to execute arbitrary commands over the network with high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community attention and media coverage, indicating a high potential for future exploitation. QNAP has released patches for affected versions, and immediate updates are strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.1CPE matchmatch criteria | cpe:2.3:o:qnap:qts:5.0.1:-:*:*:*:*:*:* | ||
5.0.1.2034CPE matchmatch criteria | cpe:2.3:o:qnap:qts:5.0.1.2034:build_20220515:*:*:*:*:*:* | ||
5.0.1.2079CPE matchmatch criteria | cpe:2.3:o:qnap:qts:5.0.1.2079:build_20220629:*:*:*:*:*:* | ||
5.0.1.2131CPE matchmatch criteria | cpe:2.3:o:qnap:qts:5.0.1.2131:build_20220820:*:*:*:*:*:* | ||
5.0.1.2137CPE matchmatch criteria | cpe:2.3:o:qnap:qts:5.0.1.2137:build_20220826:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.