An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later
History

Fri, 22 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap media Streaming Add-on
CPEs cpe:2.3:a:qnap:media_streaming_add-on:-:*:*:*:*:*:*:*
Vendors & Products Qnap
Qnap media Streaming Add-on
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
Description An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later
Title Media Streaming add-on
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published: 2024-11-22T15:31:47.697Z

Updated: 2024-11-22T16:48:42.193Z

Reserved: 2024-10-24T03:41:08.490Z

Link: CVE-2024-50395

cve-icon Vulnrichment

Updated: 2024-11-22T16:48:37.911Z

cve-icon NVD

Status : Received

Published: 2024-11-22T16:15:32.417

Modified: 2024-11-22T16:15:32.417

Link: CVE-2024-50395

cve-icon Redhat

No data.