EXPOSURES › CVE-2023-47565
CVE-2023-47565
HIGH ⌖ ON CISA KEV · EXPLOITEDQNAP VioStor NVR allows authenticated attackers to execute OS commands via network, enabling remote code execution.
This OS command injection vulnerability in QNAP VioStor NVR allows authenticated users to execute arbitrary commands via the network, creating a critical RCE risk for DIB organizations relying on QNAP surveillance hardware. Because the vulnerability is listed in CISA KEV and linked to ransomware campaigns, it represents a high-urgency supply-chain and data-breach exposure that requires immediate patching and network segmentation.
Shame score — A high-severity RCE flaw in a widely deployed NVR product that is actively exploited in the wild and linked to ransomware, despite being a known vulnerability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.