Medium severity5.9NVD Advisory· Published Sep 6, 2024· Updated Jun 17, 2026
CVE-2024-21904
CVE-2024-21904
Description
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
27cpe:2.3:o:qnap:qts:5.1.0.2348:build_20230325:*:*:*:*:*:*+ 12 more
- cpe:2.3:o:qnap:qts:5.1.0.2348:build_20230325:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.0.2399:build_20230515:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.0.2418:build_20230603:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.0.2444:build_20230629:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.0.2466:build_20230721:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.1.2491:build_20230815:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.2.2533:build_20230926:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.3.2578:build_20231110:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.4.2596:build_20231128:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.5.2645:build_20240116:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.5.2679:build_20240219:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:5.1.6.2722:build_20240402:*:*:*:*:*:*
- (no CPE)range: before 5.1.7.2770 build 20240520
cpe:2.3:o:qnap:quts_hero:h5.1.0.2409:build_20230525:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:qnap:quts_hero:h5.1.0.2409:build_20230525:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.0.2424:build_20230609:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.0.2453:build_20230708:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.0.2466:build_20230721:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.1.2488:build_20230812:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.2.2534:build_20230927:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:build_20231110:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.4.2596:build_20231128:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.5.2647:build_20240118:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.5.2680:build_20240220:*:*:*:*:*:*
- cpe:2.3:o:qnap:quts_hero:h5.1.6.2734:build_20240414:*:*:*:*:*:*
- (no CPE)range: before h5.1.7.2770 build 20240520
- Range: 5.1.x
- Range: h5.1.x
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-24-23nvdVendor Advisory
News mentions
0No linked articles in our index yet.