First published: Fri Mar 07 2025(Updated: )
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <5.2.3.3006 | |
QNAP QuTS hero | <5.2.3.3006 |
We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53697 is considered a critical severity vulnerability affecting several QNAP operating system versions.
Exploitation of CVE-2024-53697 could allow remote attackers with administrator access to modify or corrupt memory.
CVE-2024-53697 affects QNAP QTS and QuTS hero versions up to and including 5.2.3.3006.
To fix CVE-2024-53697, ensure that your QNAP system is updated to the latest patch provided by QNAP.
Currently, no specific workarounds for CVE-2024-53697 have been documented; applying the latest updates is recommended.