CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
Low
EPSS
Percentile
9.5%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total
A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access data or perform actions that they should not be allowed to perform via unspecified vectors.
QuTScloud, is not affected.
We have already fixed the vulnerability in the following versions:
QTS 5.2.0.2737 build 20240417 and later
QuTS hero h5.2.0.2782 build 20240601 and later
[
{
"cpes": [
"cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*"
],
"vendor": "qnap",
"product": "qts",
"versions": [
{
"status": "affected",
"version": "5.1.x",
"lessThan": "5.2.0.2737",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.0.x"
},
{
"status": "affected",
"version": "4.5.x"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*"
],
"vendor": "qnap",
"product": "quts_hero",
"versions": [
{
"status": "affected",
"version": "h5.1.x",
"lessThan": "h5.2.0.2782",
"versionType": "custom"
},
{
"status": "affected",
"version": "h5.0.x"
},
{
"status": "affected",
"version": "h4.5.x"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:qnap:qutscloud:c5.0.0:*:*:*:*:*:*:*"
],
"vendor": "qnap",
"product": "qutscloud",
"versions": [
{
"status": "affected",
"version": "c5.0.0",
"lessThan": "h5.2.0.2782",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
Low
EPSS
Percentile
9.5%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total