Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-47565: Vulnerability Affecting Legacy VioStor NVR - Security Advisory

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in the following versions:

QVR Firmware 5.0.0 and later

CVE
#vulnerability#ios#js#auth

Security ID : QSA-23-48

  • Release date : December 9, 2023

  • CVE identifier : CVE-2023-47565

  • Affected products: QVR Firmware 4.x

Summary

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in QVR Firmware 5.0.0 on June 21, 2014:

Affected Product

Fixed Version

QVR Firmware 4.x

QVR Firmware 5.x and later

Recommendation

To mitigate the vulnerability, ensure you apply strong passwords for all user accounts.

To further secure your device, we highly recommend updating QVR to the latest version.

Changing User Passwords in QVR

  1. Log on to QVR.
  2. Go to Control Panel > Privilege > Users.
  3. Identify the user you want to edit.
    Note: Only administrators can change the passwords of other users.
  4. Click the Change Password icon.
  5. Specify a new, strong password.
  6. Verify the password.
  7. Click Apply.

Updating QVR Firmware

  1. Log on to QVR as an administrator.
  2. Go to Control Panel > System Settings > Firmware Update.
  3. Select the Firmware Update tab.
  4. Click Browse… to upload the latest firmware file.
    Tip: Download the latest firmware file for your specific model from https://www.qnap.com/go/download. Select “Legacy NVR” to locate your model.
  5. Click Update System.
    QVR installs the update.

Attachment

  • CVE-2023-47565.json

Acknowledgements: Chad Seaman and Larry Cashdollar of Akamai Technologies reported this vulnerability to CISA.

Revision History:
V1.0 (December 09, 2023) - Published

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907