Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-21902

CVE-2024-21902: QNAP QTS Information Disclosure Flaw

CVE-2024-21902 is an information disclosure vulnerability in QNAP QTS caused by incorrect permission assignment. Authenticated attackers can read or modify critical resources. This article covers technical details, affected versions, impact, and mitigation strategies.

Updated:

CVE-2024-21902 Overview

CVE-2024-21902 is an incorrect permission assignment for critical resource vulnerability affecting QNAP QTS and QuTS hero operating systems. The flaw allows authenticated users to read or modify protected resources over the network, undermining the access control model of the NAS platform. QNAP addressed the issue in QTS 5.1.7.2770 build 20240520 and QuTS hero h5.1.7.2770 build 20240520. The weakness is categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).

Critical Impact

Authenticated network-adjacent attackers can read or modify protected NAS resources, compromising the confidentiality and integrity of files and configuration data stored on affected QNAP devices.

Affected Products

  • QNAP QTS 5.1.x versions prior to 5.1.7.2770 build 20240520
  • QNAP QuTS hero h5.1.x versions prior to h5.1.7.2770 build 20240520
  • QNAP NAS appliances running the affected firmware builds listed in QSA-24-23

Discovery Timeline

  • 2024-05-21 - CVE-2024-21902 published to NVD
  • 2024-05-20 - QNAP releases fixed builds QTS 5.1.7.2770 and QuTS hero h5.1.7.2770
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-21902

Vulnerability Analysis

The vulnerability stems from incorrect permission assignment on a critical resource within QNAP QTS and QuTS hero. An authenticated user with low privileges can reach a resource that should be restricted to administrative accounts. Because the access-control check is missing or misapplied, the resource can be both read and modified over the network. The result is a breach of confidentiality and integrity for data governed by the NAS access-control model.

QNAP has not published exploitation details in QSA-24-23, and no public proof-of-concept exploit is currently available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is an authorization defect: the affected component evaluates the caller's identity but fails to enforce the correct permission set on a sensitive resource. This is a classic broken access control pattern where authentication is verified but authorization is not consistently applied at the resource boundary.

Attack Vector

Exploitation requires network access to the QNAP NAS and a valid authenticated session. An attacker with a low-privilege account, or an adversary who has obtained user credentials through phishing or credential reuse, can invoke the vulnerable interface and interact with the restricted resource. User interaction is not required, and the attack complexity is low. Because many QNAP appliances are exposed to the internet for remote file access, the population of reachable targets is substantial.

See the QNAP Security Advisory QSA-24-23 for vendor guidance and version-specific fix details.

Detection Methods for CVE-2024-21902

Indicators of Compromise

  • Unexpected modifications to system configuration files or shared folders on QNAP NAS devices running unpatched QTS or QuTS hero builds
  • Authenticated sessions from low-privilege accounts accessing resources normally reserved for administrators
  • Anomalous outbound data transfers from NAS appliances to external hosts following user logins

Detection Strategies

  • Inventory all QNAP appliances and compare running firmware against the fixed builds QTS 5.1.7.2770 and QuTS hero h5.1.7.2770
  • Review QNAP system and access logs for authentication events from accounts that subsequently accessed administrative endpoints
  • Correlate NAS authentication logs with file-access and configuration-change events to identify privilege boundary violations

Monitoring Recommendations

  • Forward QTS and QuTS hero system logs to a centralized SIEM or data lake for continuous analysis
  • Alert on repeated authentication attempts from non-administrative accounts followed by access to restricted paths
  • Monitor network traffic to and from QNAP devices for unusual protocols, ports, or destination endpoints

How to Mitigate CVE-2024-21902

Immediate Actions Required

  • Upgrade QTS installations to 5.1.7.2770 build 20240520 or later immediately
  • Upgrade QuTS hero installations to h5.1.7.2770 build 20240520 or later immediately
  • Audit user accounts on affected NAS devices and remove or disable accounts that are no longer required
  • Rotate credentials for any account that may have interacted with the vulnerable device prior to patching

Patch Information

QNAP has released fixed firmware in QTS 5.1.7.2770 build 20240520 and QuTS hero h5.1.7.2770 build 20240520. Administrators should apply the update through the QTS Control Panel under Firmware Update, or download the image directly from the QNAP support portal. Full details are available in the QNAP Security Advisory QSA-24-23.

Workarounds

  • Restrict NAS management interfaces to trusted management networks using firewall rules or VLAN segmentation
  • Disable remote access features such as myQNAPcloud until the firmware update has been applied
  • Enforce strong, unique passwords and enable two-factor authentication for all NAS user accounts
  • Remove unnecessary user accounts and apply the principle of least privilege to all remaining accounts
bash
# Verify installed QTS or QuTS hero version via SSH
getcfg System Version -f /etc/config/uLinux.conf
getcfg System "Build Number" -f /etc/config/uLinux.conf

# Restrict management access to a trusted subnet (example iptables rule)
iptables -A INPUT -p tcp --dport 8080 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8080 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.