PT-2024-24843 · Qnap · Qnap Qts+1

Aliz Hammond

+1

·

Published

2024-09-06

·

Updated

2024-09-20

·

CVE-2024-32771

CVSS v3.1

2.6

Low

VectorAV:A/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions QNAP QTS versions prior to 5.2.0.2782 build 20240601 QNAP QuTS hero versions prior to h5.2.0.2782 build 20240601
Description An improper restriction of excessive authentication attempts issue has been reported to affect several QNAP operating system versions. If exploited, the issue could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors. QuTScloud is not affected.
Recommendations For QNAP QTS versions prior to 5.2.0.2782 build 20240601, update to QTS 5.2.0.2782 build 20240601 or later. For QNAP QuTS hero versions prior to h5.2.0.2782 build 20240601, update to QuTS hero h5.2.0.2782 build 20240601 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2024-32771

Affected Products

Qnap Qts
Quts Hero