CVE-2023-47568: QTS, QuTS hero, QuTScloud
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47568?
CVE-2023-47568 is classified as a critical SQL injection vulnerability impacting several versions of QNAP operating systems.
How do I fix CVE-2023-47568?
To fix CVE-2023-47568, update your QNAP operating system to version QTS 5.1.5.2645 or later.
Who is affected by CVE-2023-47568?
CVE-2023-47568 affects authenticated users of QNAP systems running vulnerable versions of the QTS and QuTS operating systems.
What type of vulnerability is CVE-2023-47568?
CVE-2023-47568 is a SQL injection vulnerability that allows authenticated users to execute malicious code.
Are there any known exploits for CVE-2023-47568?
As of now, there are no publicly reported exploits, but the vulnerability poses a significant risk if left unpatched.