CVE-2024-21899
Published Mar 8, 2024
Last updated 8 months ago
Overview
- Description
- An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
- Source
- security@qnapsecurity.com.tw
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- security@qnapsecurity.com.tw
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A029FCE-B575-452B-9C62-2D38B770D0A5", "versionEndExcluding": "4.5.4.2627" }, { "criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C618F95C-508C-4F21-AA57-08A738B0B625", "versionEndExcluding": "5.1.3.2578", "versionStartIncluding": "5.1.0" }, { "criteria": "cpe:2.3:o:qnap:qts:4.5.4.2627:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "320AEB7E-E07B-42AE-8F71-795A516BA5EA" }, { "criteria": "cpe:2.3:o:qnap:qts:5.1.3.2578:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34ACC24E-E1E8-4014-8DF7-9A85F3D45FF1" }, { "criteria": "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AFC9334D-F187-400C-8E53-4F746C524047", "versionEndExcluding": "h4.5.4.2626" }, { "criteria": "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2CA49EF2-1EB9-422E-8A26-BA79FFA915A2", "versionEndExcluding": "h5.1.3.2578", "versionStartIncluding": "h5.1.0" }, { "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.4.2626:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CFA8519-D4C0-4ADC-A06B-7694943B06E7" }, { "criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53222633-E4D8-453D-9A0E-E170CC163D0B" }, { "criteria": "cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F240677F-D84E-464E-B612-B583EE3D877F", "versionEndExcluding": "c5.1.5.2651" } ], "operator": "OR" } ] } ]