ZDI-CAN-22496: ZDI-24-826: (Pwn2Own) QNAP TS-464 Improper Validation Authentication Bypass Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-32766.
Affected Software
1 affected component
QNAP TS-464
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22496?
The severity of ZDI-CAN-22496 is rated at 9.8 on the CVSS scale.
2
How does ZDI-CAN-22496 affect QNAP TS-464 devices?
ZDI-CAN-22496 allows remote attackers to bypass authentication on affected QNAP TS-464 NAS devices.
3
Is authentication required to exploit ZDI-CAN-22496?
No, authentication is not required to exploit ZDI-CAN-22496.
4
What is the potential impact of ZDI-CAN-22496?
The potential impact of ZDI-CAN-22496 is unauthorized access to the affected NAS devices.
5
How can I mitigate the risks associated with ZDI-CAN-22496?
To mitigate the risks of ZDI-CAN-22496, ensure your QNAP TS-464 NAS devices are updated with the latest security patches.