First published: Fri Mar 07 2025(Updated: )
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QuTS hero h5.1.9.2954 build 20241120 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | >5.1.9.2954 | |
QNAP QuTS hero | >5.1.9.2954 |
We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QuTS hero h5.1.9.2954 build 20241120 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38638 is considered a critical vulnerability due to its potential to allow remote attackers to manipulate memory.
To mitigate CVE-2024-38638, update your QNAP QTS or QuTS hero to any version 5.2.x or later.
CVE-2024-38638 affects QNAP QTS and QuTS hero versions prior to 5.2.x.
Yes, CVE-2024-38638 can be exploited by remote attackers who have gained administrator access.
CVE-2024-38638 is an out-of-bounds write vulnerability that may lead to memory corruption.