QID 731239

Date Published: 2024-03-11

QID 731239: QNAP QTS OS Multiple Security Vulnerabilities (QSA-24-09)

QTS is the operating system for all entry-level and mid-level QNAP NAS models.

CVE-2024-21899: If exploited, the improper authentication vulnerability could allow users to compromise the security of the system via a network. CVE-2024-21900: If exploited, the injection vulnerability could allow authenticated users to execute commands via a network. CVE-2024-21901: If exploited, the SQL injection vulnerability could allow authenticated administrators to inject malicious code via a network.

Affected Versions:
QNAP QTS from 5.1.0.2348 build 20230325 prior to 5.1.3.2578 build 20231110.
QNAP QTS from 4.5.1.1456 build 20201015 prior to 4.5.4.2627 build 20231225.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Successful exploitation of the vulnerability could allow authenticated administrators to inject malicious code via a network which compromise the security of the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.2 severity.
  • Solution
    The vendor has released a patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-24-09
    Vendor References

    CVEs related to QID 731239

    Software Advisories
    Advisory ID Software Component Link
    QSA-24-09 URL Logo www.qnap.com/en/security-advisory/qsa-24-09