PT-2024-4539 · Qnap · Qts+1
Aliz Hammond
·
Published
2024-05-21
·
Updated
2024-09-11
·
CVE-2024-21902
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
QTS versions prior to 5.1.7.2770 build 20240520
QuTS hero versions prior to h5.1.7.2770 build 20240520
Description:
The issue is related to an incorrect permission assignment for a critical resource in QNAP operating systems, which could allow authenticated users to read or modify the resource via a network. This could potentially enable remote execution of arbitrary code.
Recommendations:
For QTS versions prior to 5.1.7.2770 build 20240520, update to QTS 5.1.7.2770 build 20240520 or later.
For QuTS hero versions prior to h5.1.7.2770 build 20240520, update to QuTS hero h5.1.7.2770 build 20240520 or later.
Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qts
Quts Hero