CVE-2023-47565 Details
Description
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
A command injection vulnerability has been identified in legacy QNAP VioStor NVR models running QVR Firmware 4.x. This vulnerability allows authenticated users to execute operating system commands over the network. The issue has been resolved in QVR Firmware 5.0.0 and later.
Users are advised to update QVR to the latest version. Instructions for updating QVR firmware are available on the QNAP website. Additionally, ensure that strong passwords are applied to all user accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 20, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47565 | CISA-ADP | US Government Resource |
| https://www.qnap.com/en/security-advisory/qsa-23-48 | CVE | Vendor Advisory |
| https://www.qnap.com/en/security-advisory/qsa-23-48 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| QNAP VioStor NVR OS Command Injection Vulnerability | Dec 21, 2023 | Jan 11, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap qvr firmware | >= 4.0.0, < 5.0.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 26, 2026 | Modified Analysis | [email protected] |
| Feb 25, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 22, 2023 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Dec 13, 2023 | Initial Analysis | [email protected] |
| Dec 8, 2023 | New CVE Received | [email protected] |