Command Injection Vulnerability in QNAP Operating Systems
CVE-2024-53692
5.1MEDIUM
Summary
A command injection vulnerability has been identified in various versions of the QNAP operating systems. This flaw may allow remote attackers, who have gained administrator access, to execute arbitrary commands on the affected systems. If left unpatched, this could potentially lead to unauthorized control and compromise of sensitive data. QNAP has addressed this issue in specific updates, and users are urged to upgrade to QTS 5.2.3.3006 build 20250108 or later, and QuTS hero h5.2.3.3006 build 20250108 or later to mitigate this risk.
Affected Version(s)
QTS 5.2.x < 5.2.3.3006 build 20250108
QuTS hero h5.2.x
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ZIEN