CyberzSOC

Publication detail
← Back to advisories & guidance

2024-049: Multiple Vulnerabilities in QNAP Products ↗ source

May 22, 2024 CERT-EU Advisory

Summary

These vulnerabilities could allow remote attackers to execute arbitrary code. It is strongly advised updating affected systems to the latest versions to mitigate these risks. The vulnerability CVE-2024-27130, with a CVSS score of 7.2, is due to improper input validation in the shared feature of QTS that could allow remote attackers to execute arbitrary code. An attacker can exploit the vulnerability through a specially crafted request that causes a buffer overflow, leading to remote code execution. Successful exploitation requires access to a specific It is strongly recommended updating affected devices to a fixed version.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-27130 7.2 High QNAP Systems Inc. QTS A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vuln…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.