nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-47565 CVE-2023-47565
HIGHCISA KEV
Legacy VioStor NVR
Record summary
CVE-2023-47565 has a selected CVSS score of 8.0 (high). CISA lists CVE-2023-47565 in KEV.
Description
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Dec 21, 2023 · CISA
- VulnCheck KEV
- Listed · Dec 14, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2023 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
VioStor NVRBrowse QNAP / VioStor NVR | CISA | Version data not supplied | |
VioStor NVRBrowse QNAP Systems Inc. / VioStor NVRDefault status: unaffected | CVE List | 4.x to < 5.0.0 | affected |
References
3cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47565 qnap.com
https://www.qnap.com/en/security-advisory/qsa-23-48