First published: Fri Sep 06 2024(Updated: )
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QTS 5.2.0.2782 build 20240601 and later QuTS hero h5.2.0.2782 build 20240601 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =5.1.0.2348-build_20230325 | |
QNAP QTS | =5.1.0.2399-build_20230515 | |
QNAP QTS | =5.1.0.2418-build_20230603 | |
QNAP QTS | =5.1.0.2444-build_20230629 | |
QNAP QTS | =5.1.0.2466-build_20230721 | |
QNAP QTS | =5.1.1.2491-build_20230815 | |
QNAP QTS | =5.1.2.2533-build_20230926 | |
QNAP QTS | =5.1.3.2578-build_20231110 | |
QNAP QTS | =5.1.4.2596-build_20231128 | |
QNAP QTS | =5.1.5.2645-build_20240116 | |
QNAP QTS | =5.1.5.2679-build_20240219 | |
QNAP QTS | =5.1.6.2722-build_20240402 | |
QNAP QTS | =5.1.7.2770-build_20240520 | |
QNAP QTS | =5.1.8.2823-build_20240712 | |
QNAP QTS | =5.2.0.2737-build_20240417 | |
QNAP QTS | =5.2.0.2744-build_20240424 | |
QNAP QuTS hero | =h5.1.0.2409-build_20230525 | |
QNAP QuTS hero | =h5.1.0.2424-build_20230609 | |
QNAP QuTS hero | =h5.1.0.2453-build_20230708 | |
QNAP QuTS hero | =h5.1.0.2466-build_20230721 | |
QNAP QuTS hero | =h5.1.1.2488-build_20230812 | |
QNAP QuTS hero | =h5.1.2.2534-build_20230927 | |
QNAP QuTS hero | =h5.1.3.2578-build_20231110 | |
QNAP QuTS hero | =h5.1.4.2596-build_20231128 | |
QNAP QuTS hero | =h5.1.5.2647-build_20240118 | |
QNAP QuTS hero | =h5.1.5.2680-build_20240220 | |
QNAP QuTS hero | =h5.1.6.2734-build_20240414 | |
QNAP QuTS hero | =h5.1.7.2770-build_20240520 | |
QNAP QuTS hero | =h5.1.7.2788-build_20240607 | |
QNAP QuTS hero | =h5.1.7.2794-build_20240613 | |
QNAP QuTS hero | =h5.1.8.2823-build_20240712 | |
QNAP QuTS hero | =h5.2.0.2737-build_20240417 |
We have already fixed the vulnerability in the following versions: QTS 5.2.0.2782 build 20240601 and later QuTS hero h5.2.0.2782 build 20240601 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32771 has been classified as a high severity vulnerability due to its potential for exploitation by authenticated administrators.
CVE-2024-32771 affects several versions of the QNAP QTS and QuTS hero operating systems.
To mitigate CVE-2024-32771, it is crucial to update to the latest version of QNAP QTS or QuTS hero that includes fixes for this vulnerability.
CVE-2024-32771 is an improper restriction of excessive authentication attempts vulnerability.
Exploitation of CVE-2024-32771 could allow local network authenticated administrators to perform an arbitrary number of authentication attempts, potentially leading to unauthorized access.