Back to overview

CVE-2023-34976

CRITICAL
10.0
CVSS 3.1
Description
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

Metadata

CVE ID
CVE-2023-34976
State
PUBLISHED
Assigner
qnap
Reserved
2023-06-08 08:26 UTC
Published
2023-10-13 19:17 UTC
Last updated
2026-01-12 09:14 UTC
Primary CWE
CWE-89
CWE-89
Vendor / Product
QNAP Systems Inc. / Video Station
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
QNAP Systems Inc. Video Station 5.7.x < 5.7.0 ( 2023/07/27 )
Weakness (CWE)
CWESourceDescription
CWE-89 cna CWE-89
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview