Lucene search

K
cveQnapCVE-2023-32976
HistoryOct 13, 2023 - 8:15 p.m.

CVE-2023-32976

2023-10-1320:15:10
CWE-78
qnap
web.nvd.nist.gov
26
cve-2023-32976
os command injection
container station
authenticated administrators
network execution

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

25.6%

An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.

We have already fixed the vulnerability in the following version:
Container Station 2.6.7.44 and later

Affected configurations

Nvd
Node
qnapcontainer_stationRange<2.6.7.44
VendorProductVersionCPE
qnapcontainer_station*cpe:2.3:o:qnap:container_station:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Container Station",
    "vendor": "QNAP Systems Inc.",
    "versions": [
      {
        "lessThan": "2.6.7.44",
        "status": "affected",
        "version": "2.6.x.x",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for CVE-2023-32976