Security Advisory

CVE-2023-41289

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-01-05 16:19:05
Last updated 2025-06-17 20:29:12
Assigner qnap
State PUBLISHED

Description

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later