CVE-2024-27130
HIGH 8.8EPSS 37.5%
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network.We have already fixed the vulnerability in the following version:QTS 5.1.7.2770 build 20240520 and laterQuTS hero h5.1.7.2770 build 20240520 and later
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L - EPSS
- 37.52% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2024-05-21
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- d0rb/CVE-2024-271302★ · 2024-05-21
- watchtowrlabs/CVE-2024-2713038★ · 2024-05-17
- dkstar11q/cve-2024-27130-poc