Exploitable Format String Vulnerability in QNAP Operating Systems
CVE-2024-50403
Currently unrated
Summary
A vulnerability involving the use of externally-controlled format strings has been identified in various QNAP operating system versions. This flaw enables remote attackers who have gained administrator access to retrieve confidential information or alter memory contents. It is crucial for users to upgrade to QTS 5.2.2.2950 build 20241114 or later and QuTS hero h5.2.2.2952 build 20241116 or later to mitigate the risks associated with this vulnerability.
References
Timeline
Vulnerability published