nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27129 CVE-2024-27129
MEDIUM
QTS, QuTS hero
Record summary
CVE-2024-27129 has a selected CVSS score of 6.4 (medium).
Description
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 5.1.x to < 5.1.7.2770 build 20240520 | affected |
QuTS heroBrowse QNAP Systems Inc. / QuTS heroDefault status: unaffected | CVE List | h5.1.x to < h5.1.7.2770 build 20240520 | affected |
Default status: affected | CVE List | 5.1.x | affected |
| 5.1.7.2770 | unaffected | ||
quts_heroBrowse qnap / quts_heroDefault status: affected | CVE List | h5.1.x | affected |
| h5.1.7.2770 | unaffected |
References
2qnap.com
https://www.qnap.com/en/security-advisory/qsa-24-23