PT-2024-5949 · Qnap · Qts+1
Huasheng_Mangguo
·
Published
2024-09-06
·
Updated
2024-09-13
·
CVE-2023-34974
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QTS versions prior to 4.5.4.2790 build 20240605
QuTS hero versions prior to h4.5.4.2626 build 20231225
Description
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. The issue is related to the failure to neutralize special elements used in the operating system command.
Recommendations
For QTS versions prior to 4.5.4.2790 build 20240605, update to version 4.5.4.2790 build 20240605 or later.
For QuTS hero versions prior to h4.5.4.2626 build 20231225, update to version h4.5.4.2626 build 20231225 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qts
Quts Hero