An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege.
We have already fixed the vulnerability in the following version:
Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-47 |
|
History
Fri, 22 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap media Streaming Add-on |
|
| CPEs | cpe:2.3:a:qnap:media_streaming_add-on:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap media Streaming Add-on |
|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |
| Title | Media Streaming add-on | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2024-11-22T15:31:47.697Z
Updated: 2024-11-22T16:48:42.193Z
Reserved: 2024-10-24T03:41:08.490Z
Link: CVE-2024-50395
Updated: 2024-11-22T16:48:37.911Z
Status : Received
Published: 2024-11-22T16:15:32.417
Modified: 2024-11-22T16:15:32.417
Link: CVE-2024-50395
No data.