CVE-2024-53699 Details
Description
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later
An out-of-bounds write vulnerability has been identified in QNAP's QTS and QuTS hero operating systems, specifically in versions 5.2.x. This vulnerability allows remote attackers with administrator access to modify or corrupt memory. The issue has been resolved in QTS 5.2.3.3006 build 20250108 and later, as well as in QuTS hero h5.2.3.3006 build 20250108 and later.
Users are advised to update to QTS 5.2.3.3006 build 20250108 or later, or to QuTS hero h5.2.3.3006 build 20250108 or later. Instructions for updating QTS or QuTS hero are available on the QNAP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-54 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap qts | 5.2.0.2737 build_20240417 5.2.0.2744 build_20240424 5.2.0.2782 build_20240601 5.2.0.2802 build_20240620 5.2.0.2823 build_20240711 5.2.0.2851 build_20240808 5.2.0.2860 build_20240817 5.2.1.2930 build_20241025 5.2.2.2950 build_20241114 |
CPE
Remediation
| |
| qnap quts hero | h5.2.0.2737 build_20240417 h5.2.0.2782 build_20240601 h5.2.0.2789 build_20240607 h5.2.0.2802 build_20240620 h5.2.0.2823 build_20240711 h5.2.0.2851 build_20240808 h5.2.0.2860 build_20240817 h5.2.1.2929 build_20241025 h5.2.1.2940 build_20241105 h5.2.2.2952 build_20241116 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Mar 7, 2025 | New CVE Received | [email protected] |