CVE-2023-47562: Photo Station
Published Feb 2, 2024
·Updated
An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Affected Software
1 affected component
QNAP Photo Station>=6.4.0<6.4.2
Remediation
Information
We have already fixed the vulnerability in the following version:
Photo Station 6.4.2 ( 2023/12/15 ) and later
Event History
Feb 2, 2024
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47562?
CVE-2023-47562 is a high-severity OS command injection vulnerability in Photo Station.
2
How do I fix CVE-2023-47562?
To fix CVE-2023-47562, update Photo Station to version 6.4.2 or later.
3
Who is affected by CVE-2023-47562?
Authenticated users of QNAP Photo Station versions prior to 6.4.2 are affected by CVE-2023-47562.
4
What can an attacker do with CVE-2023-47562?
An attacker can execute commands on the server via a network if CVE-2023-47562 is exploited.
5
Is there a workaround for CVE-2023-47562?
There is no documented workaround for CVE-2023-47562; upgrading to the patched version is recommended.