Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7qq-vfrc-p9vr

Опубликовано: 21 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.

We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.

We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

EPSS

Процентиль: 65%
0.00482
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.4
nvd
больше 1 года назад

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость операционных систем QTS, QuTS hero сетевых устройств Qnap, связанная с неправильным присвоением разрешений для критичного ресурса, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 65%
0.00482
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-200