CVE-2023-23369
Summary
| CVE | CVE-2023-23369 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-03 17:15:00 UTC |
| Updated | 2023-11-15 16:29:00 UTC |
| Description | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
Multimedia Console 2.1.2 ( 2023/05/04 ) and later
Multimedia Console 1.4.8 ( 2023/05/05 ) and later
QTS 5.1.0.2399 build 20230515 and later
QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.4.2451 build 20230621 and later
QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.6 build 20230621 and later
Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later
Media Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.0 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.1 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.10 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.3 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.4 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.5 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.6 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.7 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.8 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.0.0.9 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.1.1.0 |
All |
All |
All |
| Application |
Qnap |
Media Streaming Add-on |
500.1.1.1 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
1.4.3 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
1.4.4 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
1.4.5 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
1.4.6 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
1.4.7 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
2.1.0 |
All |
All |
All |
| Application |
Qnap |
Multimedia Console |
2.1.1 |
All |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20170517 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20190322 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20190730 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20190921 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20191107 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20200109 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20200421 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20200611 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20200821 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20210327 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20211215 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20220304 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20220623 |
All |
All |
| Operating System |
Qnap |
Qts |
4.2.6 |
build_20221028 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.0174 |
build_20170503 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.0868 |
build_20190322 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.0998 |
build_20190730 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1051 |
build_20190921 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1098 |
build_20191107 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1161 |
build_20200109 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1252 |
build_20200409 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1315 |
build_20200611 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1386 |
build_20200821 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1432 |
build_20201006 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1624 |
build_20210416 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1677 |
build_20210608 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1693 |
build_20210624 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1799 |
build_20211008 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1864 |
build_20211212 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.1945 |
build_20220303 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.2057 |
build_20220623 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.3.2211 |
build_20221124 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.0899 |
build_20190322 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1029 |
build_20190730 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1082 |
build_20190921 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1190 |
build_20200107 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1282 |
build_20200408 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1368 |
build_20200703 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1417 |
build_20200821 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1463 |
build_20201006 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1632 |
build_20210324 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1652 |
build_20210413 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.1976 |
build_20220303 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.2107 |
build_20220712 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.4.2242 |
build_20221124 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0895 |
build_20190328 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0907 |
build_20190409 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0923 |
build_20190425 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0944 |
build_20190516 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0959 |
build_20190531 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0979 |
build_20190620 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.0993 |
build_20190704 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1013 |
build_20190724 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1033 |
build_20190813 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1070 |
build_20190919 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1154 |
build_20191212 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1218 |
build_20200214 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1263 |
build_20200330 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1286 |
build_20200422 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1333 |
build_20200608 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1411 |
build_20200825 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1446 |
build_20200929 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1620 |
build_20210322 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1663 |
build_20210504 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1711 |
build_20210621 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1750 |
build_20210730 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1831 |
build_20211019 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1907 |
build_20220103 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.1965 |
build_20220302 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.2050 |
build_20220526 |
All |
All |
| Operating System |
Qnap |
Qts |
4.3.6.2232 |
build_20221124 |
All |
All |
| Operating System |
Qnap |
Qts |
5.1.0.2348 |
build_20230325 |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Vulnerability in QTS, Multimedia Console, and Media Streaming add-on - Security Advisory | QNAP |
MISC |
www.qnap.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730969 QNAP QTS Command Injection Vulnerability (QSA-23-35)