Out-of-Bounds Write Vulnerability in QNAP Operating Systems
CVE-2024-53697

2.1LOW

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 March 2025

Summary

An out-of-bounds write vulnerability has been identified in several versions of the QNAP operating system. This issue enables remote attackers, with administrative privileges, to modify or corrupt memory, potentially compromising system integrity. Affected users are urged to upgrade to QTS 5.2.3.3006 build 20250108 or later, as well as QuTS hero h5.2.3.3006 build 20250108 or later, to mitigate this risk. For further details, refer to the security advisory.

Affected Version(s)

QTS 5.2.x < 5.2.3.3006 build 20250108

QuTS hero h5.2.x

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

binhnt
.