CVE-2024-32771: QNAP QTS
Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication attempts via unspecified vectors. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QTS 5.2.0.2782 build 20240601 and later QuTS hero h5.2.0.2782 build 20240601 and later
Affected products
- QNAP QTS: version 5.1.0.2348 only; version 5.1.0.2399 only; version 5.1.0.2418 only; version 5.1.0.2444 only; version 5.1.0.2466 only; version 5.1.1.2491 only; …
- QNAP Quts Hero: version h5.1.0.2409 only; version h5.1.0.2424 only; version h5.1.0.2453 only; version h5.1.0.2466 only; version h5.1.1.2488 only; version h5.1.2.2534 only; …
Published 2024-09-06. Last modified 2026-06-17.