← Back

CVE-2024-37041

nvd nist
Published: Nov 22, 2024Modified: Sep 23, 2025

JSON object

Loading...
5.1
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@qnapsecurity.com.tw (Secondary)

Description

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

Affected (14)

Products: Qnap: Qts, Quts Hero
2 products
Qts
Quts Hero
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 5.2.0.2737 build_20240417
Version 5.2.0.2744 build_20240424
Version 5.2.0.2782 build_20240601
Version 5.2.0.2802 build_20240620
Version 5.2.0.2823 build_20240711
Version 5.2.0.2851 build_20240808
Version 5.2.0.2860 build_20240817
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version h5.2.0.2737 build_20240417
Version h5.2.0.2782 build_20240601
Version h5.2.0.2789 build_20240607
Version h5.2.0.2802 build_20240620
Version h5.2.0.2823 build_20240711
Version h5.2.0.2851 build_20240808
Version h5.2.0.2860 build_20240817

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.