Record summary

CVE-2023-47565 has a selected CVSS score of 8.0 (high). CISA lists CVE-2023-47565 in KEV.

Description

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Dec 21, 2023 · CISA
VulnCheck KEV
Listed · Dec 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2023 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unaffected

CVE List4.x to < 5.0.0affected

References

3