CVE-2023-23373: QUSBCam2
Published Oct 20, 2023
·Updated
An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later
Affected Software
1 affected component
QNAP QUSBCam2>=2.0.0<2.0.3
Remediation
Information
We have already fixed the vulnerability in the following version:
QUSBCam2 2.0.3 ( 2023/06/15 ) and later
Event History
Oct 20, 2023
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23373?
CVE-2023-23373 is an OS command injection vulnerability in QUSBCam2 that allows users to execute commands via a network.
2
How severe is CVE-2023-23373?
CVE-2023-23373 has a severity rating of 8.8 (high).
3
How does CVE-2023-23373 affect QUSBCam2?
CVE-2023-23373 affects QUSBCam2 by allowing users to execute commands via a network if the vulnerability is exploited.
4
Which versions of QUSBCam2 are affected by CVE-2023-23373?
Versions of QUSBCam2 between 2.0.0 and 2.0.3 are affected by CVE-2023-23373.
5
How can I fix CVE-2023-23373?
To fix CVE-2023-23373, update QUSBCam2 to version 2.0.3 or later.