VYPR
Medium severity5.9NVD Advisory· Published Mar 8, 2024· Updated Jun 17, 2026

CVE-2023-34980

CVE-2023-34980

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following versions: QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Qnap/Qts3 versions
    cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: >=4.5.1,<4.5.4.2627
    • cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*
    • (no CPE)range: QTS 4.5.4.2627 build 20231225 and later
  • Qnap/Quts Hero3 versions
    cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*range: >=h4.5.0,<h4.5.4.2626
    • cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:-:*:*:*:*:*:*
    • (no CPE)range: h4.5.4.2626 build 20231225 and later
  • Range: 4.5.x
  • Range: h4.5.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.