CVE-2024-50388

Published Dec 6, 2024

Last updated 3 months ago

Overview

Description
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later
Source
security@qnapsecurity.com.tw
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security@qnapsecurity.com.tw
CWE-77

Social media

Hype score
Not currently trending
  1. [CVE-2024-50388: CRITICAL] Critical OS command injection vulnerability in HBS 3 Hybrid Backup Sync fixed in version 25.1.1.673, preventing remote attack execution. Update now to secure your data.#cybersecurity,#vulnerability https://t.co/dNjUptCE0p https://t.co/tOe4D46acC

    @CveFindCom

    6 Dec 2024

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-50388 An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute co… https://t.co/8VNz7hRyqm

    @CVEnew

    6 Dec 2024

    271 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Am 29. Oktober 2024 veröffentlichte QNAP einen Sicherheitshinweis bezüglich einer kritischen OS-Befehlsinjektionsschwachstelle, die als CVE-2024-50388 verfolgt wird. Hier finden Sie die Empfehlungen von Arctic Wolf. #EndCyberRisk https://t.co/cO9KmQWnlJ

    @rfrumm

    11 Nov 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. QNAP fixes NAS backup software zero-day exploited at Pwn2Own: https://t.co/T9KPAGjfus QNAP has patched a critical zero-day vulnerability, CVE-2024-50388, in HBS 3 Hybrid Backup Sync version 25.1.x, exploited during Pwn2Own Ireland 2024. The OS command injection flaw allowed… htt

    @securityRSS

    31 Oct 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-50387,CVE-2024-50388 alert 🚨 QNAP: SQL injection and command injection The vulnerability is actively exploited in the wild and has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSecurity #InfoSec #QNAP https://t.co/csBn1ikdir

    @Patrowl_io

    31 Oct 2024

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Threat Alert: QNAP Patches Critical Zero-Day Exploited at Pwn2Own Ireland 2024 - CVE-2024-5038 CVE-2024-50388 CVE-2024-50387 Severity: ⚠️ Critical Maturity: 🧨 Trending Learn more: https://t.co/gif42IcLZ7 #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    31 Oct 2024

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. QNAP fixes CVE-2024-50388 that's exploited in Pwn2Own Ireland #CVE-2024-50388 #QNAP #Pwn2Own https://t.co/XfKT7OV6aQ

    @pravin_karthik

    30 Oct 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. QNAP Patches Critical Zero-Day Exploited at #Pwn2Own Ireland 2024 - CVE-2024-50388 #QNAP swiftly addresses critical zero-day CVE-2024-50388 flaw in HBS 3 Hybrid Backup Sync software, preventing potential security breaches https://t.co/2gSk0Xv6lq

    @the_yellow_fall

    30 Oct 2024

    395 Impressions

    0 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. QNAP、Pwn2Ownで実証されたNAS向けソフトウェアのゼロデイを修正(CVE-2024-50388) | Codebook|Security News https://t.co/g9eSZwGEpv

    @01ra66it

    30 Oct 2024

    68 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. QNAP fixed NAS backup zero-day demonstrated at Pwn2Own Ireland 2024: QNAP fixed critical zero-day CVE-2024-50388 which was demonstrated against a TS-464 NAS device during the Pwn2Own Ireland 2024 competition. QNAP addressed a critical zero-day… https://t.co/XuNuyBkdqI https://t.c

    @shah_sheikh

    30 Oct 2024

    28 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2024-50388: OS Command Injection in QNAP NAS, critical rating 🔥 Vuln exploited on Pwn2Own allows remote attackers to execute commands. More then 113k instances at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/Y8vTCnJktB #cybersecurity #vulnerability_map #qnap_nas https:/

    @Netlas_io

    30 Oct 2024

    868 Impressions

    3 Retweets

    16 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  12. 🛑 Le fabricant 𝗤𝗡𝗔𝗣 a corrigé une 𝗳𝗮𝗶𝗹𝗹𝗲 𝗱𝗲 𝘀𝗲́𝗰𝘂𝗿𝗶𝘁𝗲́ 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆 dans son application de sauvegarde pour 𝗡𝗔𝗦 : CVE-2024-50388. 👉 Plus d'infos dans notre article : https://t.co/2rQ0ywJhtT #QNAP #NAS #cybersecurite #infosec https://t.co/2rQ0ywJhtT

    @ITConnect_fr

    30 Oct 2024

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 In just 5 days, QNAP patched a zero-day vulnerability (CVE-2024-50388) exploited at Pwn2Own 2024. The flaw in HBS 3 Hybrid Backup Sync allowed remote attackers to execute arbitrary commands. The fix is available in version 25.1.1.673 and later. Good job @QNAPsys https://t.

    @Ransom_DB

    29 Oct 2024

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes