CVE-2024-32765

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*

History

10 Dec 2025, 22:02

Type Values Removed Values Added
References () https://www.qnap.com/en/security-advisory/qsa-24-14 - () https://www.qnap.com/en/security-advisory/qsa-24-14 - Vendor Advisory
First Time Qnap qts
Qnap quts Hero
Qnap
Summary
  • (es) Se ha informado que una vulnerabilidad afecta la red y el conmutador virtual. Si se explota, la vulnerabilidad podría permitir a los administradores locales autenticados obtener acceso y ejecutar ciertas funciones a través de vectores no especificados. Ya hemos solucionado la vulnerabilidad en las siguientes versiones: QTS 5.1.8.2823 build 20240712 y posteriores QuTS hero h5.1.8.2823 build 20240712 y posteriores
CPE cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*

12 Aug 2024, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 13:38

Updated : 2025-12-10 22:02


NVD link : CVE-2024-32765

Mitre link : CVE-2024-32765

CVE.ORG link : CVE-2024-32765


JSON object : View

Products Affected

qnap

  • qts
  • quts_hero
CWE
CWE-291

Reliance on IP Address for Authentication

CWE-306

Missing Authentication for Critical Function