9.8
CVSSv3

CVE-2024-21899

Published: 08/03/2024 Updated: 13/03/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to make arbitrary changes to configuration on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privWizard API endpoints. The issue results from the lack of proper validation of a user-supplied string before using it to update configuration. An attacker can leverage this vulnerability to change the configuration of the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qnap qts 5.1.3.2578

qnap quts hero h5.1.3.2578

qnap qts 4.5.4.2627

qnap quts hero h4.5.4.2626

qnap qts

qnap qutscloud

qnap quts hero

Github Repositories

Critical RCE CVE-2024-21899 Vulnerability in QNAP Products

CVE-2024-21899-RCE Critical RCE CVE-2024-21899 Vulnerability in QNAP Products Date of published 27/03/2024 🔥 CVSS: 98/10 Description QNAP recently addressed three vulnerabilities affecting their QTS, QuTS hero, QuTScloud, and myQNAPcloud products One of these vulnerabilities is of critical severity, marking a concerning development in the vulnerability landscape These vu

Critical CVE-2024-21899 Vulnerability in QNAP Products

CVE-2024-21899-RCE Critical RCE CVE-2024-21899 Vulnerability in QNAP Products Date of published 2024/03/12 🔥 CVSS: 98/10 Description QNAP recently addressed three vulnerabilities affecting their QTS, QuTS hero, QuTScloud, and myQNAPcloud products One of these vulnerabilities is of critical severity, marking a concerning development in the vulnerability landscape These vu

Critical CVE-2024-21899 Vulnerability in QNAP Products

CVE-2024-21899 Critical CVE-2024-21899 Vulnerability in QNAP Products

Recent Articles

QNAP warns of critical auth bypass flaw in its NAS devices
BleepingComputer • Bill Toulas • 08 Mar 2024

QNAP warns of critical auth bypass flaw in its NAS devices By Bill Toulas March 8, 2024 03:03 PM 0 QNAP warns of vulnerabilities in its NAS software products, including QTS, QuTS hero, QuTScloud, and myQNAPcloud, that could allow attackers to access devices. The Taiwanese Network Attached Storage (NAS) device maker disclosed three vulnerabilities that can lead to an authentication bypass, command injection, and SQL injection. While the last two require the attackers to be authenticated...