CVE-2024-21902Sensitive Information Exposure in Systems INC QTS

Severity
8.1HIGHNVD
CNA6.4
EPSS
0.5%
top 34.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21

Description

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

CVEListV5qnap_systems_inc/quts_heroh5.1.xh5.1.7.2770 build 20240520
NVDqnap/quts_hero11 versions+10
CVEListV5qnap_systems_inc/qts5.1.x5.1.7.2770 build 20240520
NVDqnap/qts12 versions+11

🔴Vulnerability Details

2
CVEList
QTS, QuTS hero2024-05-21
GHSA
GHSA-v7qq-vfrc-p9vr: An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions2024-05-21
CVE-2024-21902 — Sensitive Information Exposure | cvebase