An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege.
We have already fixed the vulnerability in the following version:
Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-24-47 |
History
Fri, 22 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Qnap
Qnap media Streaming Add-on |
|
CPEs | cpe:2.3:a:qnap:media_streaming_add-on:-:*:*:*:*:*:*:* | |
Vendors & Products |
Qnap
Qnap media Streaming Add-on |
|
Metrics |
ssvc
|
Fri, 22 Nov 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |
Title | Media Streaming add-on | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: qnap
Published: 2024-11-22T15:31:47.697Z
Updated: 2024-11-22T16:48:42.193Z
Reserved: 2024-10-24T03:41:08.490Z
Link: CVE-2024-50395
Vulnrichment
Updated: 2024-11-22T16:48:37.911Z
NVD
Status : Received
Published: 2024-11-22T16:15:32.417
Modified: 2024-11-22T16:15:32.417
Link: CVE-2024-50395
Redhat
No data.