CVE-2024-21899
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the syst...
Affects 3 products across 1 vendor.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
An improper authentication vulnerability in QNAP operating systems could allow unauthorized access to the system via a network.
BSID: BS-2024-GLOBAL-051428-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-21899?
What is the CVSS score for CVE-2024-21899?
Is CVE-2024-21899 actively exploited?
How do I remediate CVE-2024-21899?
What systems are affected by CVE-2024-21899?
| CVE ID | CVE-2024-21899 |
|---|---|
| BSID | BS-2024-GLOBAL-051428-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2024-03-08 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Source: NIST NVD / MITRE CVE Database
The vulnerability is related to improper authentication mechanisms, which could be exploited by an attacker to gain unauthorized access to the system.
Exploitation Likelihood: HIGH
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 685ef5a69d94dd79bf6f0e7d0c54d7460bc362b4ddf1d4bd353a69566909a209aea4b0e7d16784d701e10313407c160e219d083bf0e8ac66ee31a981505a7b32 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →