QTS, QuTS hero, QuTScloud
55Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 24%
from disclosure to weapon
Published on NVDMar 8
VulnCheck+10d
exploitation probability
24%top 2% of all CVEs
observed exploitation
yesVulnCheck
In short
QNAP NAS systems have a flaw that allows attackers to bypass login authentication and gain unauthorized access over the network without valid credentials. This is critical because it gives attackers full control of the device and any data stored on it.
Technical detail
An improper authentication vulnerability (CWE-287) in QNAP QTS, QuTS hero, and QuTScloud allows unauthenticated network-based attackers to compromise system security by bypassing authentication mechanisms. The vulnerability affects multiple OS versions prior to specified patch releases and could result in complete system compromise with CVSS 9.8 severity.
Summary generated and translated by AI from the official description.
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuTS hero h4.5.4.2626 build 20231225 and later
QuTScloud c5.1.5.2651 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H