CVE-2024-27130: QTS, QuTS hero
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network.
We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27130?
CVE-2024-27130 has been assessed as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-27130?
To fix CVE-2024-27130, update to the latest version of QTS, specifically versions 5.1.7 or higher.
Which versions of QTS are affected by CVE-2024-27130?
CVE-2024-27130 affects QTS versions from 5.1.0.2348 to 5.1.6.2722.
Can CVE-2024-27130 be exploited remotely?
Yes, CVE-2024-27130 can be exploited remotely over a network if the conditions are met.
What type of vulnerability is CVE-2024-27130?
CVE-2024-27130 is a buffer copy without checking size of input vulnerability.