CVE-2023-47565

CVE Published 2023-12-08
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) qnap
Related Product(s) qvr_firmware
Exploitation Reported (CISA KEV) 2023-12-21
CVSS 3 Base Score 8.0 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector ADJACENT_NETWORK

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in the following versions:

QVR Firmware 5.0.0 and later

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References