Out-of-Bounds Write Vulnerability in QNAP Operating Systems
CVE-2024-53699

2.1LOW

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 March 2025

Summary

An out-of-bounds write vulnerability has been identified in several versions of QNAP's operating systems, notably QTS and QuTS hero. This flaw, if exploited, allows remote attackers with administrator access to potentially manipulate or compromise system memory. This can lead to unauthorized alterations of critical data or system configurations, necessitating prompt updates to safeguard against possible attacks. QNAP has released patches addressing this vulnerability in QTS version 5.2.3.3006 build 20250108 and later, as well as in QuTS hero version h5.2.3.3006 build 20250108 and later.

Affected Version(s)

QTS 5.2.x < 5.2.3.3006 build 20250108

QuTS hero h5.2.x

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

binhnt
.