Integer overflow in QNAP Systems, Inc. products - CVE-2024-21905

 

Integer overflow in QNAP Systems, Inc. products - CVE-2024-21905

Published: April 29, 2024


Vulnerability identifier: #VU89038
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21905
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow. A remote user can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

QuTScloud
QuTS hero
QNAP QTS

How to mitigate CVE-2024-21905

Install updates from vendor's website.

QuTScloud - update to c5.1.5.2651
QuTS hero - update to h5.1.3.2578 build 20231110
QNAP QTS - update to 5.1.3.2578 20231110

External References

Related Security Bulletins