CVE-2023-39297: QTS, QuTS hero, QuTScloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39297?
The severity of CVE-2023-39297 has been classified as high due to its potential to allow authenticated users to execute OS commands remotely.
How do I fix CVE-2023-39297?
To fix CVE-2023-39297, it is recommended to update to the latest QTS version where the vulnerability has been patched.
Which QNAP versions are affected by CVE-2023-39297?
CVE-2023-39297 affects multiple QNAP QTS versions including 4.5.4.x up to 5.1.4.x prior to the fix.
Who is vulnerable to CVE-2023-39297?
Authenticated users of affected QNAP systems may exploit CVE-2023-39297 to execute arbitrary commands.
What are the potential consequences of exploiting CVE-2023-39297?
Exploiting CVE-2023-39297 could lead to unauthorized command execution, compromising the system's integrity.