Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2024-21899

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

  • Published: Mar 8, 2024
  • Updated: Mar 14, 2024
  • CVE: CVE-2024-21899
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Software From Fixed in
qnap / qts 5.1.3.2578 5.1.3.2578.x
qnap / quts_hero h5.1.3.2578 h5.1.3.2578.x
qnap / qts 4.5.4.2627 4.5.4.2627.x
qnap / quts_hero h4.5.4.2626 h4.5.4.2626.x
qnap / qts - 4.5.4.2627
qnap / qutscloud - c5.1.5.2651
qnap / qts 5.1.0 5.1.3.2578
qnap / quts_hero - h4.5.4.2626
qnap / quts_hero h5.1.0 h5.1.3.2578