CVE-2024-13086Sensitive Information Exposure in Systems INC Quts Hero

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.1%
top 65.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7

Description

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later QuTS hero h5.2.0.2851 build 20240808 and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5qnap_systems_inc/quts_heroh5.xQuTS hero h5.2.0.2851 build 20240808
NVDqnap/quts_heroh5.0.0h5.2.0.2851
CVEListV5qnap_systems_inc/qts5.xQTS 5.2.0.2851 build 20240808
NVDqnap/qts5.0.05.2.0.2851

🔴Vulnerability Details

2
CVEList
QTS, QuTS hero2025-03-07
GHSA
GHSA-rfr3-g285-rggj: An exposure of sensitive information vulnerability has been reported to affect product2025-03-07
CVE-2024-13086 — Sensitive Information Exposure | cvebase