Back to overview

CVE-2024-32764

CRITICAL
9.9
CVSS 3.1
Description
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following version: myQNAPcloud Link 2.4.51 and later

Metadata

CVE ID
CVE-2024-32764
State
PUBLISHED
Assigner
qnap
Reserved
2024-04-18 08:14 UTC
Published
2024-04-26 15:00 UTC
Last updated
2024-08-02 02:20 UTC
Primary CWE
CWE-306
CWE-306
Vendor / Product
QNAP Systems Inc. / myQNAPcloud Link
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
QNAP Systems Inc. myQNAPcloud Link 2.4.x < 2.4.51
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306
CWE-346 cna CWE-346
CWE-749 cna CWE-749
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Back to overview