← back
CVE-2024-21899criticalobserved exploitationCWE-287

QTS, QuTS hero, QuTScloud

55Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 24%
from disclosure to weapon
Published on NVDMar 8
VulnCheck+10d
exploitation probability
24%top 2% of all CVEs
observed exploitation
yesVulnCheck
In short

QNAP NAS systems have a flaw that allows attackers to bypass login authentication and gain unauthorized access over the network without valid credentials. This is critical because it gives attackers full control of the device and any data stored on it.

Technical detail

An improper authentication vulnerability (CWE-287) in QNAP QTS, QuTS hero, and QuTScloud allows unauthenticated network-based attackers to compromise system security by bypassing authentication mechanisms. The vulnerability affects multiple OS versions prior to specified patch releases and could result in complete system compromise with CVSS 9.8 severity.

Summary generated and translated by AI from the official description.
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H