CVE-2024-27129: QTS, QuTS hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network.
We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27129?
CVE-2024-27129 is classified as a high severity vulnerability that could allow authenticated users to execute code via a network.
How do I fix CVE-2024-27129?
To fix CVE-2024-27129, users should upgrade to a patched version of the QNAP QTS operating system or QuTS hero as specified in the security advisory.
Which QNAP versions are affected by CVE-2024-27129?
CVE-2024-27129 affects various versions of QNAP QTS and QuTS hero, specifically versions between 5.1.0.2348 and 5.1.6.2734.
Can CVE-2024-27129 be exploited remotely?
Yes, CVE-2024-27129 can potentially be exploited remotely by authenticated users.
What type of vulnerability is CVE-2024-27129?
CVE-2024-27129 is a buffer copy without checking the size of input vulnerability.