2.4

CVE-2024-32771

QTS, QuTS hero

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors.
QuTScloud is not affected.

We have already fixed the vulnerability in the following versions:
QTS 5.2.0.2782 build 20240601 and later
QuTS hero h5.2.0.2782 build 20240601 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.1.0.2348 Update build_20230325
Qnap ≫ Qts Version 5.1.0.2399 Update build_20230515
Qnap ≫ Qts Version 5.1.0.2418 Update build_20230603
Qnap ≫ Qts Version 5.1.0.2444 Update build_20230629
Qnap ≫ Qts Version 5.1.0.2466 Update build_20230721
Qnap ≫ Qts Version 5.1.1.2491 Update build_20230815
Qnap ≫ Qts Version 5.1.2.2533 Update build_20230926
Qnap ≫ Qts Version 5.1.3.2578 Update build_20231110
Qnap ≫ Qts Version 5.1.4.2596 Update build_20231128
Qnap ≫ Qts Version 5.1.5.2645 Update build_20240116
Qnap ≫ Qts Version 5.1.5.2679 Update build_20240219
Qnap ≫ Qts Version 5.1.6.2722 Update build_20240402
Qnap ≫ Qts Version 5.1.7.2770 Update build_20240520
Qnap ≫ Qts Version 5.1.8.2823 Update build_20240712
Qnap ≫ Qts Version 5.2.0.2737 Update build_20240417
Qnap ≫ Qts Version 5.2.0.2744 Update build_20240424
Qnap ≫ Quts Hero Version h5.1.0.2409 Update build_20230525
Qnap ≫ Quts Hero Version h5.1.0.2424 Update build_20230609
Qnap ≫ Quts Hero Version h5.1.0.2453 Update build_20230708
Qnap ≫ Quts Hero Version h5.1.0.2466 Update build_20230721
Qnap ≫ Quts Hero Version h5.1.1.2488 Update build_20230812
Qnap ≫ Quts Hero Version h5.1.2.2534 Update build_20230927
Qnap ≫ Quts Hero Version h5.1.3.2578 Update build_20231110
Qnap ≫ Quts Hero Version h5.1.4.2596 Update build_20231128
Qnap ≫ Quts Hero Version h5.1.5.2647 Update build_20240118
Qnap ≫ Quts Hero Version h5.1.5.2680 Update build_20240220
Qnap ≫ Quts Hero Version h5.1.6.2734 Update build_20240414
Qnap ≫ Quts Hero Version h5.1.7.2770 Update build_20240520
Qnap ≫ Quts Hero Version h5.1.7.2788 Update build_20240607
Qnap ≫ Quts Hero Version h5.1.7.2794 Update build_20240613
Qnap ≫ Quts Hero Version h5.1.8.2823 Update build_20240712
Qnap ≫ Quts Hero Version h5.2.0.2737 Update build_20240417
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.095
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.4 0.9 1.4
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
security@qnapsecurity.com.tw 2.6 1 1.4
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

https://www.qnap.com/en/security-advisory/qsa-24-28
Vendor Advisory