high Known exploitedREV. 01
CVE-2023-47565QNAP VioStor — video recorders that take shell commands
These legacy network video recorders (QNAP VioStor) let a logged-in user push commands into the underlying operating system over the network. Firmware 4.x carries the flaw, and the fix is the move to firmware 5.0.0 or later.
Read the risk
THE VITAL STATS- CVSS score
- 8.8/ 10 CVSS v3.1
- EPSS probability
- 73% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2023-12-08
- Added to KEV
- 2023-12-21
- Exploit published
- Not recorded
- Confidence
- high
- Kill chain
- execution
- MITRE ATT&CK
- T1059
- Severity
- high
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attacker needsThe attacker needs an account on the device.
Fixed inQVR Firmware >= 5.0.0
Behind the card
3 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisoryqnap.comqnap.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-09-24 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.