Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:qnap:qts:5.1.0.2348:build_20230325:*:*:*:*:*:*", "matchCriteriaId": "39382CBA-EA68-426A-AC07-A9A26E722CAB", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.0.2399:build_20230515:*:*:*:*:*:*", "matchCriteriaId": "BCB37C08-1DF7-4AF4-9BB1-C562E5643B5A", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.0.2418:build_20230603:*:*:*:*:*:*", "matchCriteriaId": "8368130C-F26D-41FE-8D78-B103A23B5327", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.0.2444:build_20230629:*:*:*:*:*:*", "matchCriteriaId": "3E0EE181-78AF-4C3C-90A4-C69A2DE6E176", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.0.2466:build_20230721:*:*:*:*:*:*", "matchCriteriaId": "56E3AE06-78DA-4844-ADC1-09A35F1C5B54", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.1.2491:build_20230815:*:*:*:*:*:*", "matchCriteriaId": "D2AA7A32-0DA8-4417-A23E-C4F563BC7819", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.2.2533:build_20230926:*:*:*:*:*:*", "matchCriteriaId": "80E7C17C-ED6D-439D-A1F3-1870A3ADA926", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.3.2578:build_20231110:*:*:*:*:*:*", "matchCriteriaId": "636C2D9C-C837-4FAC-B79D-1CA7A7C1FF3E", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.4.2596:build_20231128:*:*:*:*:*:*", "matchCriteriaId": "866B455B-0266-4990-920B-A06756ED5A61", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.5.2645:build_20240116:*:*:*:*:*:*", "matchCriteriaId": "B3B5C4C5-5EE2-4E6F-927E-1D52A04895BB", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.5.2679:build_20240219:*:*:*:*:*:*", "matchCriteriaId": "543E17BB-B552-4B65-B028-BE9A47E6F34B", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:qts:5.1.6.2722:build_20240402:*:*:*:*:*:*", "matchCriteriaId": "EEDC247A-96D9-4140-AA72-52E4EEDC2121", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.0.2409:build_20230525:*:*:*:*:*:*", "matchCriteriaId": "6CA398A8-EBDF-4D41-B15E-7B763F885021", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.0.2424:build_20230609:*:*:*:*:*:*", "matchCriteriaId": "F63A5ED2-ECC2-49A0-BFA9-548E35ACD6C7", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.0.2453:build_20230708:*:*:*:*:*:*", "matchCriteriaId": "53387FAC-7BE0-47D7-99BF-2B1F03C17CC3", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.0.2466:build_20230721:*:*:*:*:*:*", "matchCriteriaId": "D4226394-0023-4CD2-BB89-77251BF92FF3", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.1.2488:build_20230812:*:*:*:*:*:*", "matchCriteriaId": "646257F7-D4A4-43B0-91F2-7850338B3CA1", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.2.2534:build_20230927:*:*:*:*:*:*", "matchCriteriaId": "88825AE1-B006-4F7F-BD90-D4B1CF1251A3", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:build_20231110:*:*:*:*:*:*", "matchCriteriaId": "3F471666-4919-4770-956E-ACE4C55D29DB", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.4.2596:build_20231128:*:*:*:*:*:*", "matchCriteriaId": "9573F671-D49E-438A-B72C-DFC390A79093", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.5.2647:build_20240118:*:*:*:*:*:*", "matchCriteriaId": "75E7938F-943F-428D-974D-42E790829F88", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.5.2680:build_20240220:*:*:*:*:*:*", "matchCriteriaId": "12F5732D-C95F-45D1-968C-C2269DFDF6D4", "vulnerable": true}, {"criteria": "cpe:2.3:o:qnap:quts_hero:h5.1.6.2734:build_20240414:*:*:*:*:*:*", "matchCriteriaId": "94734596-A56A-4128-A39A-7E22FBD17835", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.\n\nWe have already fixed the vulnerability in the following version:\nQTS 5.1.7.2770 build 20240520 and later\nQuTS hero h5.1.7.2770 build 20240520 and later"}, {"lang": "es", "value": " Se ha informado que una vulnerabilidad de asignaci\u00f3n incorrecta de permisos para recursos cr\u00edticos afecta a varias versiones del sistema operativo QNAP. Si se explota, la vulnerabilidad podr\u00eda permitir a los usuarios autenticados leer o modificar el recurso a trav\u00e9s de una red. Ya hemos solucionado la vulnerabilidad en la siguiente versi\u00f3n: QTS 5.1.7.2770 build 20240520 y posteriores QuTS hero h5.1.7.2770 build 20240520 y posteriores"}], "id": "CVE-2024-21902", "lastModified": "2024-11-21T08:55:14.060", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", "version": "3.1"}, "exploitabilityScore": 3.1, "impactScore": 2.7, "source": "security@qnapsecurity.com.tw", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 8.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.2, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2024-05-21T16:15:24.743", "references": [{"source": "security@qnapsecurity.com.tw", "tags": ["Vendor Advisory"], "url": "https://www.qnap.com/en/security-advisory/qsa-24-23"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://www.qnap.com/en/security-advisory/qsa-24-23"}], "sourceIdentifier": "security@qnapsecurity.com.tw", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-200"}, {"lang": "en", "value": "CWE-732"}], "source": "security@qnapsecurity.com.tw", "type": "Secondary"}]}