CVE-2023-47565
Legacy VioStor NVR
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- November 06, 2023
- Published Date
- December 08, 2023
- Last Updated
- February 03, 2025
- Vendor
- QNAP Systems Inc.
- Product
- VioStor NVR
- Description
- An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
CVSS Scores
CVSS v3.1
8.0 - HIGH
Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (added 2023-12-21 00:00:00 UTC) Source
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-12-21 00:00:00 UTC |