CVE-2023-41283: QTS, QuTS hero, QuTScloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41283?
CVE-2023-41283 is classified as a critical severity OS command injection vulnerability.
How do I fix CVE-2023-41283?
To fix CVE-2023-41283, update to one of the patched software versions provided by QNAP.
What versions of QNAP QTS are affected by CVE-2023-41283?
QNAP QTS versions 5.1.0.2348 to 5.1.4.2596 are affected by CVE-2023-41283.
Who is affected by CVE-2023-41283?
Authenticated administrators using vulnerable QNAP operating system versions are affected by CVE-2023-41283.
Can CVE-2023-41283 be exploited remotely?
Yes, CVE-2023-41283 can be exploited remotely via a network by authenticated users.