PT-2024-7401 · Qnap · Hbs 3 Hybrid Backup Sync
Published
2024-10-29
·
Updated
2026-01-30
·
CVE-2024-50388
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
HBS 3 Hybrid Backup Sync versions prior to 25.1.1.673
Description:
The issue is related to an OS command injection vulnerability. This vulnerability could allow remote attackers to execute commands. It is reported that over 113,000 instances are potentially affected. The vulnerability was exploited at Pwn2Own, allowing attackers to carry out remote command execution.
Recommendations:
For HBS 3 Hybrid Backup Sync versions prior to 25.1.1.673, update to version 25.1.1.673 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable software to minimize the risk of exploitation.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hbs 3 Hybrid Backup Sync