login
quiescence.eu
Saltar al contenido

CVE-2023-47565

QNAP VioStor NVR OS Command Injection Vulnerability

n/a
CVSS
73.3%
EPSS (exploit prob.)
99.4%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2023-12-21
Added

MITRE ATT&CK techniques

How this vulnerability maps to adversary behaviour, from the Center for Threat-Informed Defense's public CVE→ATT&CK mappings. Use it to check whether your detections already cover the technique.

TechniqueNameRelationship
T1203 Exploitation for Client Execution exploitation technique
T1496 Resource Hijacking primary impact
T1498 Network Denial of Service secondary impact

Summary

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

Affected software

Vendor: QNAP  ·  Product: VioStor NVR

Weakness types (CWE):

CWE-78

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in QNAP

CVENameEPSSExploited
CVE-2019-7195 QNAP Photo Station Path Traversal Vulnerability 89.7% Yes
CVE-2019-7192 QNAP Photo Station Improper Access Control Vulnerability 88.2% Yes
CVE-2022-27593 QNAP Photo Station Externally Controlled Reference Vulnerability 87.9% Yes
CVE-2019-7194 QNAP Photo Station Path Traversal Vulnerability 83.0% Yes
CVE-2021-28799 QNAP NAS Improper Authorization Vulnerability 78.3% Yes
CVE-2020-2509 QNAP Network-Attached Storage (NAS) Command Injection Vulnerability 33.4% Yes
CVE-2018-19949 QNAP NAS File Station Command Injection Vulnerability 24.4% Yes
CVE-2018-19953 QNAP NAS File Station Cross-Site Scripting Vulnerability 23.9% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.