Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-50358

27
FAUCET Score

CVE-2023-50358 is an OS command injection vulnerability impacting several QNAP QTS, QuTS hero, and QuTScloud operating system versions. Successful exploitation could allow an unauthenticated attacker on the same network segment to execute arbitrary commands, leading to limited impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, the vulnerability has garnered some community discussion. QNAP has released patches for affected versions, and immediate updates are recommended.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.2.0, < 4.2.6CPE matchmatch criteria
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
>= 4.3.0, < 4.3.3.2644CPE matchmatch criteria
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
>= 4.3.4, < 4.3.4.2675CPE matchmatch criteria
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
>= 4.3.5, < 4.3.6.2665CPE matchmatch criteria
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
>= 4.5.1, < 4.5.4.2627CPE matchmatch criteria
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.8MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.52%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1352 is in the 100th percentile among its peer group of 1,749 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

unit42.paloaltonetworks.com / qnap-qts-firmware-cve-2023-50358
ExploitThird Party Advisory
bsi.bund.de / SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213941-1032
Third Party Advisory
qnap.com / en/security-advisory/qsa-23-57
Vendor Advisory