AV AC PR UI S C I A CVSS EPSS %ile KEV A L L N U H H H 8.0 .7328 99.4 YES
AFFECTED Product Versions Fixed VioStor NVR 4.x – —
TIMELINE Nov 6 Reserved by qnap Dec 8 Published (CNA: qnap) Dec 21 Added to CISA KEV, remediation due 2024-01-11
Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV A L L N U H H H 8.0 .7328 99.4 YES
AFFECTED Product Versions Fixed VioStor NVR 4.x – —
TIMELINE Nov 6 Reserved by qnap Dec 8 Published (CNA: qnap) Dec 21 Added to CISA KEV, remediation due 2024-01-11
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
| Date | Event | Detail |
|---|---|---|
| November 6, 2023 | Reserved | Reserved by qnap |
| December 8, 2023 | Published | Published (CNA: qnap) |
| December 21, 2023 | KEV ADDED | Added to CISA KEV, remediation due 2024-01-11 |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| QNAP Systems Inc. | VioStor NVR | — | 4.x | — |
Authoritative record: CVE-2023-47565 at cve.org
Vendors: qnap systems
Weaknesses: CWE-78
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-47565 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.