CVE-2024-32765Reliance on IP Address for Authentication in Systems INC Quts Hero

Severity
4.2MEDIUMNVD
EPSS
0.0%
top 90.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 0.8 | Impact: 3.4

Affected Packages4 packages

NVDqnap/quts_heroh5.1.0h5.1.8.2823
CVEListV5qnap_systems_inc/quts_heroh5.1.xh5.1.8.2823 build 20240712
NVDqnap/qts5.1.05.1.8.2823
CVEListV5qnap_systems_inc/qts5.1.x5.1.8.2823 build 20240712

🔴Vulnerability Details

2
GHSA
GHSA-3hfh-c9pr-r52q: A vulnerability has been reported to affect Network & Virtual Switch2024-08-12
CVEList
QTS, QuTS hero2024-08-09
CVE-2024-32765 — Systems INC Quts Hero vulnerability | cvebase