QNAP Fixes Improper Authentication Vulnerability Affecting Multiple Versions of QTS

CVE-2024-21899
9.8CRITICAL

Key Information

Vendor
QNAP
Status
Qts
Quts Hero
Qutscloud
Vendor
CVE Published:
8 March 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The articles discuss a critical authentication bypass vulnerability (CVE-2024-21899) affecting multiple versions of QNAP operating systems. This vulnerability allows unauthorized remote access to the NAS device, posing a severe security risk. The vulnerability has been addressed by QNAP with patches available for affected versions. Other vulnerabilities impacting QNAP operating systems are also highlighted, emphasizing the need for immediate updates to mitigate potential security risks. The exploitation of these vulnerabilities could lead to unauthorized access, data compromise, and further attacks, making it crucial for organizations and individuals using QNAP products to prioritize security updates.

Affected Version(s)

QTS < 5.1.3.2578 build 20231110

QTS < 4.5.4.2627 build 20231225

QuTS hero < h5.1.x

News Articles

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • First article discovered by securityonline.info

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)5 News Article(s)

Credit

ZDI-CAN-22493/22494 : DEVCORE
.