VDB

GCVE-110-NCSC-2024-467

GCVE-110-NCSC-2024-467
Advisory Published
Vulnetix · Advisory published December 9, 2024
QNAP heeft kwetsbaarheden verholpen in verschillende versies van hun besturingssystemen, waaronder QTS en QuTS hero.

Weaknesses (CWE)

CWE-287Improper AuthenticationCWE-295Improper Certificate ValidationCWE-177Improper Handling of URL Encoding (Hex Encoding)CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-134Use of Externally-Controlled Format String

Affected Products

VendorProductVersionsPlatforms
qnap_systems_inc.quts_hero
qnapquts_hero
qnap_systems_inc.qts
qnapqts

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›