Buffer Overflow Vulnerability in QNAP Operating System
CVE-2024-56805

5.3MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
6 June 2025

What is CVE-2024-56805?

A buffer overflow vulnerability has been identified in the QNAP operating system, impacting multiple versions. This flaw can be exploited by remote attackers who have acquired user access, enabling them to alter memory or cause processes to crash. QNAP has released fixes for this issue in QTS 5.2.4.3079 build 20250321 and later, alongside updates for QuTS hero in the same build number. Users are advised to upgrade to the latest versions to mitigate potential risks.

Affected Version(s)

QTS 5.2.x < 5.2.4.3079 build 20250321

QuTS hero h5.2.x

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Searat and izut
.
CVE-2024-56805 : Buffer Overflow Vulnerability in QNAP Operating System