{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-38639",
        "assignerOrgId": "2fd009eb-170a-4625-932b-17a53af1051f",
        "state": "PUBLISHED",
        "assignerShortName": "qnap",
        "dateReserved": "2024-06-19T00:17:01.279Z",
        "datePublished": "2026-09-18T06:51:06.187Z",
        "dateUpdated": "2026-09-18T06:51:06.187Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "2fd009eb-170a-4625-932b-17a53af1051f",
                "shortName": "qnap",
                "dateUpdated": "2026-09-18T06:51:06.187Z"
            },
            "title": "QTS",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-287",
                            "description": "CWE-287",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-115",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-115"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "QNAP Systems Inc.",
                    "product": "QTS",
                    "versions": [
                        {
                            "status": "unaffected",
                            "version": "?"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability in the following version:",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.<br>QTS is not affected.<br><br>We have already fixed the vulnerability in the following version:<br>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.qnap.com/en/security-advisory/qsa-24-37"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "LOW",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 4.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "We have already fixed the vulnerability in the following version:",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "We have already fixed the vulnerability in the following version:<br>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Luís Almeida Teles",
                    "type": "finder"
                }
            ],
            "source": {
                "advisory": "QSA-24-37",
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.1.0-dev"
            }
        }
    }
}