CVE-2023-23364: Multimedia Console
A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.
We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 ) and later Multimedia Console 1.4.7 ( 2023/03/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this QNAP operating system vulnerability?
The vulnerability ID for this QNAP operating system vulnerability is CVE-2023-23364.
What is the severity of CVE-2023-23364?
CVE-2023-23364 has a severity value of 9.8, which is considered critical.
Which QNAP software is affected by CVE-2023-23364?
The QNAP Multimedia Console versions up to 2.1.1 and 1.4.7 are affected by CVE-2023-23364.
What is the impact of CVE-2023-23364?
If exploited, CVE-2023-23364 could potentially allow remote users to execute code via unspecified vectors.
How can I fix CVE-2023-23364?
To fix CVE-2023-23364, update your QNAP Multimedia Console to version 2.1.1 or higher.