CVE-2023-39302: QTS, QuTS hero, QuTScloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39302?
CVE-2023-39302 is considered a serious vulnerability due to the potential for authenticated administrators to execute arbitrary commands remotely.
How do I fix CVE-2023-39302?
To mitigate CVE-2023-39302, update your QNAP operating system to one of the patched versions specified in the security advisory.
Which versions of QNAP are affected by CVE-2023-39302?
CVE-2023-39302 affects several versions of QNAP, including QTS 5.1.0.2348, 5.1.0.2399, 5.1.0.2418, and others up to 5.1.3.2578.
What types of systems are affected by CVE-2023-39302?
CVE-2023-39302 affects QNAP's QTS, QuTS hero, and QuTScloud operating systems.
Is CVE-2023-39302 remote exploit capable?
Yes, CVE-2023-39302 can be exploited remotely by authenticated administrators to execute commands.