VYPR
Medium severity5.8NVD Advisory· Published Feb 13, 2024· Updated Jun 17, 2026

CVE-2023-47218

CVE-2023-47218

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • Qnap/Qts3 versions
    cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: >=5.1.0,<5.1.5.2645
    • cpe:2.3:o:qnap:qts:5.1.5.2645:-:*:*:*:*:*:*
    • (no CPE)range: before 5.1.5.2645 build 20240116
  • Qnap/Quts Hero3 versions
    cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*range: >=h5.1.0,<h5.1.5.2647
    • cpe:2.3:o:qnap:quts_hero:h5.1.5.2647:-:*:*:*:*:*:*
    • (no CPE)range: before 5.1.5.2647 build 20240118
  • Qnap/QuTScloud2 versions
    cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*range: >=c5.0.0.1919,<c5.1.5.2651
    • (no CPE)range: before c5.1.5.2651
  • Range: 5.1.x
  • Range: h5.1.x
  • Range: c5.x

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.