PT-2024-4539 · Qnap · Qts+1

Aliz Hammond

·

Published

2024-05-21

·

Updated

2024-09-11

·

CVE-2024-21902

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: QTS versions prior to 5.1.7.2770 build 20240520 QuTS hero versions prior to h5.1.7.2770 build 20240520
Description: The issue is related to an incorrect permission assignment for a critical resource in QNAP operating systems, which could allow authenticated users to read or modify the resource via a network. This could potentially enable remote execution of arbitrary code.
Recommendations: For QTS versions prior to 5.1.7.2770 build 20240520, update to QTS 5.1.7.2770 build 20240520 or later. For QuTS hero versions prior to h5.1.7.2770 build 20240520, update to QuTS hero h5.1.7.2770 build 20240520 or later.

Fix

Information Disclosure

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2024-05043
CVE-2024-21902

Affected Products

Qts
Quts Hero