CVE-2024-13086

MEDIUM

QNAP QTS and QuTS hero - Exposure of Sensitive Information

Title source: llm
STIX 2.1

Description

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later QuTS hero h5.2.0.2851 build 20240808 and later

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 36.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
qnap/qts 5.0.0 - 5.2.0.2851
qnap/quts_hero h5.0.0 - h5.2.0.2851
Published Mar 07, 2025
Tracked Since Feb 18, 2026