CVE-2024-56805
Severity CVSS v4.0:
MEDIUM
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
06/06/2025
Last modified:
09/06/2025
Description
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes.<br />
<br />
We have already fixed the vulnerability in the following versions:<br />
QTS 5.2.4.3079 build 20250321 and later<br />
QuTS hero h5.2.4.3079 build 20250321 and later
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM