First published: Fri Mar 07 2025(Updated: )
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <5.2.3.3006 | |
QNAP QuTS hero | <5.2.3.3006 |
We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53699 has a high severity rating due to the potential for remote attackers to exploit the out-of-bounds write vulnerability.
To fix CVE-2024-53699, update your QNAP QTS or QuTS hero to version 5.2.3.3007 or later.
CVE-2024-53699 affects users of QNAP QTS and QuTS hero operating systems versions up to 5.2.3.3006.
Exploitation of CVE-2024-53699 requires that the attacker has gained administrator access to the system.
If CVE-2024-53699 is exploited, it could allow attackers to modify or corrupt memory, leading to potential denial of service or data breaches.