CVE-2023-41289: QcalAgent
Published Jan 5, 2024
·Updated
An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later
Affected Software
1 affected component
QNAP QcalAgent>=1.1.0<1.1.8
Remediation
Information
We have already fixed the vulnerability in the following version:
QcalAgent 1.1.8 and later
Event History
Jan 5, 2024
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41289?
CVE-2023-41289 is classified as a critical OS command injection vulnerability.
2
How do I fix CVE-2023-41289?
To fix CVE-2023-41289, update QcalAgent to version 1.1.8 or later.
3
Who is affected by CVE-2023-41289?
Authenticated users of QcalAgent versions prior to 1.1.8 are affected by CVE-2023-41289.
4
What could happen if CVE-2023-41289 is exploited?
If exploited, CVE-2023-41289 could allow authenticated users to execute arbitrary commands on the system.
5
Is there a patch available for CVE-2023-41289?
Yes, the patch is included in QcalAgent version 1.1.8 and later.