CVE-2024-53691

HIGH EPSS 97.1%
Published Dec 6, 20241y ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
High
Find Similar
Published Dec 6, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and later

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
97.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-59

Affected Products 33

VendorProductVersionRange
qnapqts5.1.0.2348any
qnapqts5.1.0.2399any
qnapqts5.1.0.2418any
qnapqts5.1.0.2444any
qnapqts5.1.0.2466any
qnapqts5.1.1.2491any
qnapqts5.1.2.2533any
qnapqts5.1.3.2578any
qnapqts5.1.4.2596any
qnapqts5.1.5.2645any
qnapqts5.1.5.2679any
qnapqts5.1.6.2722any
qnapqts5.1.7.2770any
qnapqts5.2.0.2737any
qnapqts5.2.0.2744any
qnapqts5.2.0.2782any
qnapquts_heroh5.1.0.2409any
qnapquts_heroh5.1.0.2424any
qnapquts_heroh5.1.0.2453any
qnapquts_heroh5.1.0.2466any
qnapquts_heroh5.1.1.2488any
qnapquts_heroh5.1.2.2534any
qnapquts_heroh5.1.3.2578any
qnapquts_heroh5.1.4.2596any
qnapquts_heroh5.1.5.2647any
qnapquts_heroh5.1.5.2680any
qnapquts_heroh5.1.6.2734any
qnapquts_heroh5.1.7.2770any
qnapquts_heroh5.1.7.2788any
qnapquts_heroh5.1.7.2794any
qnapquts_heroh5.2.0.2737any
qnapquts_heroh5.2.0.2782any
qnapquts_heroh5.2.0.2789any

References 1

  • qnap.com https://www.qnap.com/en/security-advisory/qsa-24-28
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.