ZDI-CAN-22378: ZDI-24-473: (Pwn2Own) QNAP TS-464 Authentication Service Improper Certificate Validation Vulnerability
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-27124.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22378?
The ZDI-CAN-22378 vulnerability has a CVSS rating of 6.5, indicating a medium severity level.
What systems are affected by ZDI-CAN-22378?
ZDI-CAN-22378 specifically affects QNAP TS-464 NAS devices.
Is authentication required to exploit ZDI-CAN-22378?
No, authentication is not required to exploit the ZDI-CAN-22378 vulnerability.
What type of attack does ZDI-CAN-22378 enable?
ZDI-CAN-22378 allows network-adjacent attackers to compromise the integrity of downloaded information.
How can I mitigate the risk of ZDI-CAN-22378?
To mitigate ZDI-CAN-22378, ensure your QNAP TS-464 NAS device is updated to the latest firmware version that addresses this vulnerability.