CVE-2024-27130
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 37.52% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120, CWE-121
- Affected
- qnap/qts · qnap/quts hero
- Source
- security@qnapsecurity.com.tw
References
- https://www.qnap.com/en/security-advisory/qsa-24-23Vendor Advisory
- https://www.qnap.com/en/security-advisory/qsa-24-23Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.