Junglewise Threat Intelligence

CVE-2023-47565: QNAP VioStor NVR OS Command Injection Vulnerability

CVE-2023-47565 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-12-21

Vendors: QNAP Systems, Inc., QNAP.

Executive brief

An OS command injection vulnerability in legacy QNAP VioStor NVR models running QVR Firmware 4.x allows authenticated users to execute arbitrary commands via the network. The vulnerability was addressed in QVR Firmware version 5.0.0 and later.

Affected products

  • QNAP Systems, Inc. QVR Firmware 4.x (specifically 4.0.0 up to but excluding 5.0.0)
  • QNAP Systems, Inc. VioStor NVR

Timeline

  • 2023-12-08: disclosed: Initial disclosure by QNAP Systems, Inc.
  • 2023-12-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-12-21: exploited: Reported as exploited in the wild.
  • 2024-01-11: other: CISA KEV remediation due date.