CVE-2024-53698

MEDIUM

Qnap Qts - Double Free

Title source: rule
STIX 2.1

Description

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

Scores

CVSS v3 4.9
EPSS 0.0017
EPSS Percentile 37.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-415
Status published
Products (19)
qnap/qts 5.2.0.2737 build_20240417
qnap/qts 5.2.0.2744 build_20240424
qnap/qts 5.2.0.2782 build_20240601
qnap/qts 5.2.0.2802 build_20240620
qnap/qts 5.2.0.2823 build_20240711
qnap/qts 5.2.0.2851 build_20240808
qnap/qts 5.2.0.2860 build_20240817
qnap/qts 5.2.1.2930 build_20241025
qnap/qts 5.2.2.2950 build_20241114
qnap/quts_hero h5.2.0.2737 build_20240417
... and 9 more
Published Mar 07, 2025
Tracked Since Feb 18, 2026