cbcvebase.
CVE-2024-53696
published 2025-03-07

CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who…

PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.41%
33.2th percentile
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later

Affected

8 ranges
VendorProductVersion rangeFixed in
qnapqts>= 4.5.1 < 4.5.4.29574.5.4.2957
qnapqulog_center>= 1.7.0 < 1.7.0.8291.7.0.829
qnapqulog_center>= 1.8.0 < 1.8.0.8881.8.0.888
qnapquts_hero>= h4.5.0 < h4.5.4.2476h4.5.4.2476
qnap_systems_incqts>= 4.5.x < 4.5.4.2957 build 202411194.5.4.2957 build 20241119
qnap_systems_incqulog_center>= 1.7.x.x < 1.7.0.829 ( 2024/10/01 )1.7.0.829 ( 2024/10/01 )
qnap_systems_incqulog_center>= 1.8.x.x < 1.8.0.888 ( 2024/10/15 )1.8.0.888 ( 2024/10/15 )
qnap_systems_incquts_hero>= h4.5.x < h4.5.4.2956 build 20241119h4.5.4.2956 build 20241119

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.