CVE-2024-50387: SMB Service
A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code.
We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50387?
CVE-2024-50387 is rated as high severity due to its potential for remote code execution through SQL injection.
How do I fix CVE-2024-50387?
To fix CVE-2024-50387, update the QNAP SMB Service to version 4.15.002 or later.
Which versions of QNAP are affected by CVE-2024-50387?
CVE-2024-50387 affects SMB Service version 4.15.001 and earlier.
Can CVE-2024-50387 be exploited remotely?
Yes, CVE-2024-50387 can be exploited remotely by attackers to inject malicious code.
What is the impact of CVE-2024-50387 if successfully exploited?
If CVE-2024-50387 is successfully exploited, it could allow remote attackers to execute arbitrary code on the affected systems.