{"api_version":"1","generated_at":"2026-09-18T07:45:44+00:00","cve":"CVE-2024-38639","urls":{"html":"https://cve.report/CVE-2024-38639","api":"https://cve.report/api/cve/CVE-2024-38639.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-38639","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-38639"},"summary":{"title":"QTS","description":"An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability in the following version:","state":"PUBLISHED","assigner":"qnap","published_at":"2026-09-18 07:16:49","updated_at":"2026-09-18 07:16:49"},"problem_types":["CWE-287","CWE-287 CWE-287"],"metrics":[{"version":"3.1","source":"security@qnapsecurity.com.tw","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-24-37","name":"https://www.qnap.com/en/security-advisory/qsa-24-37","refsource":"security@qnapsecurity.com.tw","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-38639","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38639","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"QNAP Systems Inc.","product":"QTS","version":"unaffected ?","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"We have already fixed the vulnerability in the following version:","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Luís Almeida Teles","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"QTS","vendor":"QNAP Systems Inc.","versions":[{"status":"unaffected","version":"?"}]}],"credits":[{"lang":"en","type":"finder","value":"Luís Almeida Teles"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.<br>QTS is not affected.<br><br>We have already fixed the vulnerability in the following version:<br>"}],"value":"An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability in the following version:"}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-287","description":"CWE-287","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T06:51:06.187Z","orgId":"2fd009eb-170a-4625-932b-17a53af1051f","shortName":"qnap"},"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-24-37"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"We have already fixed the vulnerability in the following version:<br>"}],"value":"We have already fixed the vulnerability in the following version:"}],"source":{"advisory":"QSA-24-37","discovery":"EXTERNAL"},"title":"QTS","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"2fd009eb-170a-4625-932b-17a53af1051f","assignerShortName":"qnap","cveId":"CVE-2024-38639","datePublished":"2026-09-18T06:51:06.187Z","dateReserved":"2024-06-19T00:17:01.279Z","dateUpdated":"2026-09-18T06:51:06.187Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 07:16:49","lastModifiedDate":"2026-09-18 07:16:49","problem_types":["CWE-287","CWE-287 CWE-287"],"metrics":{"cvssMetricV31":[{"source":"security@qnapsecurity.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":2.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"38639","Ordinal":"1","Title":"QTS","CVE":"CVE-2024-38639","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"38639","Ordinal":"1","NoteData":"An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability in the following version:","Type":"Description","Title":"QTS"}]}}}