← Back

CVE-2024-38641

nvd nist
Published: Sep 6, 2024Modified: Sep 16, 2024

JSON object

Loading...
7.3
Vector
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@qnapsecurity.com.tw (Secondary)

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

Affected (27)

Products: Qnap: Qts, Quts Hero
2 products
Qts
Quts Hero
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 5.1.0.2348 build_20230325
Version 5.1.0.2399 build_20230515
Version 5.1.0.2418 build_20230603
Version 5.1.0.2444 build_20230629
Version 5.1.0.2466 build_20230721
Version 5.1.1.2491 build_20230815
Version 5.1.2.2533 build_20230926
Version 5.1.3.2578 build_20231110
Version 5.1.4.2596 build_20231128
Version 5.1.5.2645 build_20240116
Version 5.1.5.2679 build_20240219
Version 5.1.6.2722 build_20240402
Version 5.1.7.2770 build_20240520
Configuration B
14 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version h5.1.0.2409 build_20230525
Version h5.1.0.2424 build_20230609
Version h5.1.0.2453 build_20230708
Version h5.1.0.2466 build_20230721
Version h5.1.1.2488 build_20230812
Version h5.1.2.2534 build_20230927
Version h5.1.3.2578 build_20231110
Version h5.1.4.2596 build_20231128
Version h5.1.5.2647 build_20240118
Version h5.1.5.2680 build_20240220
Version h5.1.6.2734 build_20240414
Version h5.1.7.2770 build_20240520
Version h5.1.7.2788 build_20240607
Version h5.1.7.2794 build_20240613

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.