Skip to content
COOEY

EXPOSURES › CVE-2023-47565

CVE-2023-47565

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-47565 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildransomwaresupply-chaindata-breachunpatched

QNAP VioStor NVR allows authenticated attackers to execute OS commands via network, enabling remote code execution.

This OS command injection vulnerability in QNAP VioStor NVR allows authenticated users to execute arbitrary commands via the network, creating a critical RCE risk for DIB organizations relying on QNAP surveillance hardware. Because the vulnerability is listed in CISA KEV and linked to ransomware campaigns, it represents a high-urgency supply-chain and data-breach exposure that requires immediate patching and network segmentation.

Shame score — A high-severity RCE flaw in a widely deployed NVR product that is actively exploited in the wild and linked to ransomware, despite being a known vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.