CVE-2024-27128
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
21/05/2024
Last modified:
11/09/2024
Description
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network.<br />
<br />
We have already fixed the vulnerability in the following version:<br />
QTS 5.1.7.2770 build 20240520 and later<br />
QuTS hero h5.1.7.2770 build 20240520 and later
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:qnap:qts:5.1.0.2348:build_20230325:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.0.2399:build_20230515:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.0.2418:build_20230603:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.0.2444:build_20230629:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.0.2466:build_20230721:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.1.2491:build_20230815:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.2.2533:build_20230926:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.3.2578:build_20231110:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.4.2596:build_20231128:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.5.2645:build_20240116:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.5.2679:build_20240219:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:qts:5.1.6.2722:build_20240402:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:quts_hero:h5.1.0.2409:build_20230525:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:quts_hero:h5.1.0.2424:build_20230609:*:*:*:*:*:* | ||
cpe:2.3:o:qnap:quts_hero:h5.1.0.2453:build_20230708:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page