First published: Fri Oct 20 2023(Updated: )
An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qusbcam2 | >=2.0.0<2.0.3 |
We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23373 is an OS command injection vulnerability in QUSBCam2 that allows users to execute commands via a network.
CVE-2023-23373 has a severity rating of 8.8 (high).
CVE-2023-23373 affects QUSBCam2 by allowing users to execute commands via a network if the vulnerability is exploited.
Versions of QUSBCam2 between 2.0.0 and 2.0.3 are affected by CVE-2023-23373.
To fix CVE-2023-23373, update QUSBCam2 to version 2.0.3 or later.