CVE-2024-53694: QVPN Device Client, Qsync, Qfinder Pro
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.
We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53694?
CVE-2024-53694 has been classified as a moderate severity vulnerability due to the potential unauthorized access it allows local attackers.
How do I fix CVE-2024-53694?
To fix CVE-2024-53694, upgrade the affected software to the latest version as recommended in the security advisory.
Which products are affected by CVE-2024-53694?
CVE-2024-53694 affects QNAP QVPN Device Client versions prior to 2.2.5, Qsync versions prior to 5.1.3, and Qfinder Pro versions prior to 7.11.1.
What type of vulnerability is CVE-2024-53694?
CVE-2024-53694 is a time-of-check time-of-use (TOCTOU) race condition vulnerability.
Can attackers exploit CVE-2024-53694 remotely?
No, CVE-2024-53694 can only be exploited by local attackers who already have user access.