QTS, QuTS hero
75Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 7.2epss 38%
from disclosure to weapon0 days
Published on NVDMay 21
1st PoCMay 17
VulnCheck+6d
exploitation probability
38%top 2% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
In short
A buffer overflow vulnerability in QNAP QTS and QuTS hero operating systems allows attackers to execute arbitrary code over the network by sending specially crafted data that exceeds expected buffer limits.
Technical detail
CWE-120/121 buffer copy vulnerability in QNAP QTS and QuTS hero enables remote code execution when the system fails to validate input size before copying to a fixed-size buffer. Exploitation requires network access and no authentication; successful exploitation grants arbitrary code execution with system privileges.
Summary generated and translated by AI from the official description.
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network.
We have already fixed the vulnerability in the following version:
QTS 5.1.7.2770 build 20240520 and later
QuTS hero h5.1.7.2770 build 20240520 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
public PoCs found — 3
vulncheckvulncheck.com/xdb/b140a4e5c640unverifiedvulncheckvulncheck.com/xdb/fd3ef1157d3dunverifiedvulncheckvulncheck.com/xdb/7677da62fd7eunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.