CVE-2024-53696

MEDIUM

QuLog Center 1.7.0-1.7.0.828, QTS 4.5.1-4.5.4.2956, QuTS hero h4.5.0-h4.5.4.2475 - SSRF

Title source: llm
STIX 2.1

Description

A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later

References (1)

Core 1
Core References

Scores

CVSS v3 4.9
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
qnap/qts 4.5.1 - 4.5.4.2957
qnap/qulog_center 1.7.0 - 1.7.0.829
qnap/quts_hero h4.5.0 - h4.5.4.2476
Published Mar 07, 2025
Tracked Since Feb 18, 2026