QNAP Operating System Vulnerability Affects Authenticated Users
Key Information
- Vendor
- QNAP
- Status
- Qts
- Quts Hero
- Qutscloud
- Vendor
- CVE Published:
- 8 March 2024
Badges
Summary
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later
Affected Version(s)
QTS < 5.1.3.2578 build 20231110
QuTS hero < h5.1.x
QuTScloud < c5.x.x
News Articles
CVE-2024-21900 Archives
VulnerabilityMarch 8, 2024CVE-2024-21899 (CVSS 9.8): Critical QNAP Flaw Opens Door to HackersQNAP has issued a critical security advisory regarding multiple vulnerabilities impacting their NAS software...
8 months ago
Multiple QNAP Vulnerabilities Let Attackers Inject Malicious Codes
QNAP has vulnerabilities within systems and applications that allow attackers to compromise system security and execute malicious commands.
8 months ago
CVSS V3.1
Timeline
First article discovered by GBHackers on Security
Vulnerability published.
Vulnerability Reserved.