Home

Description

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

PUBLISHED Reserved 2024-10-24 | Published 2024-11-22 | Updated 2024-11-22 | Assigner qnap




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639

Product status

Default status
unaffected

500.1.x (custom) before 500.1.1.6 ( 2024/08/02 )
affected

Credits

Dohwan KIM (neko_hat from TeamH4C) finder

References

www.qnap.com/en/security-advisory/qsa-24-47

cve.org (CVE-2024-50395)

nvd.nist.gov (CVE-2024-50395)

Download JSON