Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-47565


An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later


Published

2023-12-08T16:15:16.367

Last Modified

2025-01-27T21:52:58.293

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qnap qvr_firmware < 5.0.0 Yes

References