8.8

CVE-2024-50397

QTS, QuTS hero

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory.

We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS hero h5.2.1.2929 build 20241025 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 5.2.0.2737 Update build_20240417
Qnap ≫ Qts Version 5.2.0.2744 Update build_20240424
Qnap ≫ Qts Version 5.2.0.2782 Update build_20240601
Qnap ≫ Qts Version 5.2.0.2802 Update build_20240620
Qnap ≫ Qts Version 5.2.0.2823 Update build_20240711
Qnap ≫ Qts Version 5.2.0.2851 Update build_20240808
Qnap ≫ Qts Version 5.2.0.2860 Update build_20240817
Qnap ≫ Quts Hero Version h5.2.0.2737 Update build_20240417
Qnap ≫ Quts Hero Version h5.2.0.2782 Update build_20240601
Qnap ≫ Quts Hero Version h5.2.0.2789 Update build_20240607
Qnap ≫ Quts Hero Version h5.2.0.2802 Update build_20240620
Qnap ≫ Quts Hero Version h5.2.0.2823 Update build_20240711
Qnap ≫ Quts Hero Version h5.2.0.2851 Update build_20240808
Qnap ≫ Quts Hero Version h5.2.0.2860 Update build_20240817
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.462
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@qnapsecurity.com.tw 7.7 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

https://www.qnap.com/en/security-advisory/qsa-24-43
Vendor Advisory