Executive brief
A QNAP NAS device has an improper authentication flaw that allows remote attackers to bypass security controls and compromise system integrity. This could enable unauthorized access to sensitive data stored on the device or allow attackers to modify system configuration without proper credentials.
Technical details
An improper authentication vulnerability exists in QNAP NAS devices, allowing remote attackers to bypass authentication mechanisms and compromise system security. The vulnerability requires network access but does not require prior authentication or user interaction. Attackers can exploit this flaw to gain unauthorized access to the system or execute unauthorized operations. QNAP has released a patch addressing this vulnerability; QTS is confirmed not affected. CVSS score 4.8 indicates moderate impact on confidentiality or integrity.
Affected products
- QNAP NAS device
Timeline
- 2024-09-18: disclosed
- 2024: patched: Fix available; QTS confirmed unaffected