mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
23 lines
1.6 KiB
Markdown
23 lines
1.6 KiB
Markdown
![]() |
### [CVE-2023-23369](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23369)
|
||
|

|
||
|

|
||
|

|
||
|
%20&color=brighgreen)
|
||
|

|
||
|
%20&color=brighgreen)
|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.We have already fixed the vulnerability in the following versions:Multimedia Console 2.1.2 ( 2023/05/04 ) and laterMultimedia Console 1.4.8 ( 2023/05/05 ) and laterQTS 5.1.0.2399 build 20230515 and laterQTS 4.3.6.2441 build 20230621 and laterQTS 4.3.4.2451 build 20230621 and laterQTS 4.3.3.2420 build 20230621 and laterQTS 4.2.6 build 20230621 and laterMedia Streaming add-on 500.1.1.2 ( 2023/06/12 ) and laterMedia Streaming add-on 500.0.0.11 ( 2023/06/16 ) and later
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
No PoCs from references.
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/yikesoftware/yikesoftware
|
||
|
|