← back
CVE-2024-21899

QTS, QuTS hero, QuTScloud

CVSS 9.8 CRITICALEPSS 24.4%CWE-287
In short

QNAP NAS systems have a flaw that allows attackers to bypass login authentication and gain unauthorized access over the network without valid credentials. This is critical because it gives attackers full control of the device and any data stored on it.

Technical detail

An improper authentication vulnerability (CWE-287) in QNAP QTS, QuTS hero, and QuTScloud allows unauthenticated network-based attackers to compromise system security by bypassing authentication mechanisms. The vulnerability affects multiple OS versions prior to specified patch releases and could result in complete system compromise with CVSS 9.8 severity.

Summary generated and translated by AI from the official description.
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →