ZDI-24-473: (Pwn2Own) QNAP TS-464 Authentication Service Improper Certificate Validation Vulnerability
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-27124.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-473?
ZDI-24-473 has a CVSS rating of 6.5, indicating a medium severity vulnerability.
What devices are affected by ZDI-24-473?
ZDI-24-473 specifically affects QNAP TS-464 NAS devices.
Can ZDI-24-473 be exploited without authentication?
Yes, ZDI-24-473 can be exploited by network-adjacent attackers without the need for authentication.
What are the potential impacts of ZDI-24-473?
ZDI-24-473 allows attackers to compromise the integrity of downloaded information on affected devices.
How can I protect my QNAP TS-464 from ZDI-24-473?
To protect against ZDI-24-473, ensure that your QNAP TS-464 is updated with the latest security patches and configurations.