← All CVEs

CVE-2024-53691

high · 8.7

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and later

8.7
CVSS
22.9%
EPSS (exploit prob.)
98th
EPSS percentile
2024-12-06
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-59

Affected products

VendorProductAffected versions
qnapqts5.1.0.2348
qnapqts5.1.0.2399
qnapqts5.1.0.2418
qnapqts5.1.0.2444
qnapqts5.1.0.2466
qnapqts5.1.1.2491
qnapqts5.1.2.2533
qnapqts5.1.3.2578
qnapqts5.1.4.2596
qnapqts5.1.5.2645
qnapqts5.1.5.2679
qnapqts5.1.6.2722
qnapqts5.1.7.2770
qnapqts5.2.0.2737
qnapqts5.2.0.2744
qnapqts5.2.0.2782
qnapquts_heroh5.1.0.2409
qnapquts_heroh5.1.0.2424
qnapquts_heroh5.1.0.2453
qnapquts_heroh5.1.0.2466
qnapquts_heroh5.1.1.2488
qnapquts_heroh5.1.2.2534
qnapquts_heroh5.1.3.2578
qnapquts_heroh5.1.4.2596
qnapquts_heroh5.1.5.2647
qnapquts_heroh5.1.5.2680
qnapquts_heroh5.1.6.2734
qnapquts_heroh5.1.7.2770
qnapquts_heroh5.1.7.2788
qnapquts_heroh5.1.7.2794
qnapquts_heroh5.2.0.2737
qnapquts_heroh5.2.0.2782
qnapquts_heroh5.2.0.2789

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-53691