8.1

CVE-2024-21902

QTS, QuTS hero

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.

We have already fixed the vulnerability in the following version:
QTS 5.1.7.2770 build 20240520 and later
QuTS hero h5.1.7.2770 build 20240520 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.1.0.2348 Update build_20230325
Qnap ≫ Qts Version 5.1.0.2399 Update build_20230515
Qnap ≫ Qts Version 5.1.0.2418 Update build_20230603
Qnap ≫ Qts Version 5.1.0.2444 Update build_20230629
Qnap ≫ Qts Version 5.1.0.2466 Update build_20230721
Qnap ≫ Qts Version 5.1.1.2491 Update build_20230815
Qnap ≫ Qts Version 5.1.2.2533 Update build_20230926
Qnap ≫ Qts Version 5.1.3.2578 Update build_20231110
Qnap ≫ Qts Version 5.1.4.2596 Update build_20231128
Qnap ≫ Qts Version 5.1.5.2645 Update build_20240116
Qnap ≫ Qts Version 5.1.5.2679 Update build_20240219
Qnap ≫ Qts Version 5.1.6.2722 Update build_20240402
Qnap ≫ Quts Hero Version h5.1.0.2409 Update build_20230525
Qnap ≫ Quts Hero Version h5.1.0.2424 Update build_20230609
Qnap ≫ Quts Hero Version h5.1.0.2453 Update build_20230708
Qnap ≫ Quts Hero Version h5.1.0.2466 Update build_20230721
Qnap ≫ Quts Hero Version h5.1.1.2488 Update build_20230812
Qnap ≫ Quts Hero Version h5.1.2.2534 Update build_20230927
Qnap ≫ Quts Hero Version h5.1.3.2578 Update build_20231110
Qnap ≫ Quts Hero Version h5.1.4.2596 Update build_20231128
Qnap ≫ Quts Hero Version h5.1.5.2647 Update build_20240118
Qnap ≫ Quts Hero Version h5.1.5.2680 Update build_20240220
Qnap ≫ Quts Hero Version h5.1.6.2734 Update build_20240414
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.269
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
security@qnapsecurity.com.tw 6.4 3.1 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://www.qnap.com/en/security-advisory/qsa-24-23
Vendor Advisory