CyberzSOC

Publication detail
← Back to advisories & guidance

2024-115: QNAP NAS Zero-Day Vulnerabilities ↗ source

October 31, 2024 CERT-EU Advisory

Summary

These vulnerabilities allow remote attackers to gain root access and execute arbitrary commands on compromised devices The vulnerability CVE-2024-50387 in QNAP’s SMB service could allow remote attackers to exploit the NAS system and potentially gain a root shell [1,3]. The vulnerability CVE-2024-50388 could allow remote attackers to execute arbitrary commands on affected devices [2,4]. CERT-EU recommends applying updates to the affected devices as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-50387 10.0 Critical QNAP Systems Inc. SMB Service A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote …
CVE-2024-50388 9.5 Critical QNAP Systems Inc. HBS 3 Hybrid Backup Sync An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.