CVE-2024-27130
high · 7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
7.2
CVSS
37.5%
EPSS (exploit prob.)
98th
EPSS percentile
2024-05-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Weaknesses
CWE-120CWE-121
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| qnap | qts | 5.1.0.2348 |
| qnap | qts | 5.1.0.2399 |
| qnap | qts | 5.1.0.2418 |
| qnap | qts | 5.1.0.2444 |
| qnap | qts | 5.1.0.2466 |
| qnap | qts | 5.1.1.2491 |
| qnap | qts | 5.1.2.2533 |
| qnap | qts | 5.1.3.2578 |
| qnap | qts | 5.1.4.2596 |
| qnap | qts | 5.1.5.2645 |
| qnap | qts | 5.1.5.2679 |
| qnap | qts | 5.1.6.2722 |
| qnap | quts_hero | h5.1.0.2409 |
| qnap | quts_hero | h5.1.0.2424 |
| qnap | quts_hero | h5.1.0.2453 |
| qnap | quts_hero | h5.1.0.2466 |
| qnap | quts_hero | h5.1.1.2488 |
| qnap | quts_hero | h5.1.2.2534 |
| qnap | quts_hero | h5.1.3.2578 |
| qnap | quts_hero | h5.1.4.2596 |
| qnap | quts_hero | h5.1.5.2647 |
| qnap | quts_hero | h5.1.5.2680 |
| qnap | quts_hero | h5.1.6.2734 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-27130