Site icon TheCyberThrone

QNAP Releases Patches for Critical Vulnerabilities -CVE-2024-32766 & CVE-2024-32764

Advertisements

QNAP,  has issued a security warning with an urgent security advisory to its users concerning multiple severe vulnerabilities across its suite of NAS software products. These flaws, if exploited, could enable attackers to perform unauthorized actions such as bypassing authentication mechanisms and executing commands remotely.

The first two vulnerabilities tracked as CVE-2024-27124 with a CVSS score of 7.5 and CVE-2024-32766 with a CVSS score 10, are an OS command injection, a technique where attackers can send malicious commands to a vulnerable system, allowing them to run arbitrary code. This could lead to data theft, installation of malware, or a complete NAS takeover.

Advertisements

The third vulnerability tracked as CVE-2024-32764 with a CVSS score of 9.9 A dangerous flaw permitting unauthorized access to critical functions within the myQNAPcloud Link service.

QNAP urges all users to update their devices immediately to the following versions, which contain the necessary security patches:

Exit mobile version