CVE-2024-53696
Status: AnalyzedMedium (5.1)—
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.
We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 5.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.45%
- Percentile among all scored CVEs: 37
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- CWE-918
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-53696",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-53696",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-07T17:54:00.666580Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 5.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "QuLog Center",
"versions": [
{
"status": "affected",
"version": "1.7.x.x",
"lessThan": "1.7.0.829 ( 2024/10/01 )",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.8.x.x",
"lessThan": "1.8.0.888 ( 2024/10/15 )",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "QNAP Systems Inc.",
"product": "QTS",
"versions": [
{
"status": "affected",
"version": "4.5.x",
"lessThan": "4.5.4.2957 build 20241119",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuTS hero",
"versions": [
{
"status": "affected",
"version": "h4.5.x",
"lessThan": "h4.5.4.2956 build 20241119",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-03-07T17:15:20.390",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-24-53",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQuLog Center 1.7.0.829 ( 2024/10/01 ) and later\nQuLog Center 1.8.0.888 ( 2024/10/15 ) and later\nQTS 4.5.4.2957 build 20241119 and later\nQuTS hero h4.5.4.2956 build 20241119 and later"
},
{
"lang": "es",
"value": "Se ha informado de una vulnerabilidad de server-side request forgery (SSRF) que afecta a QuLog Center. Si se explota, la vulnerabilidad podría permitir a atacantes remotos que hayan obtenido acceso de administrador leer datos de la aplicación. Ya hemos corregido la vulnerabilidad en las siguientes versiones: QuLog Center 1.7.0.829 (2024/10/01) y posteriores QuLog Center 1.8.0.888 (2024/10/15) y posteriores QTS 4.5.4.2957 compilación 20241119 y posteriores QuTS hero h4.5.4.2956 compilación 20241119 y posteriores"
}
],
"lastModified": "2026-06-17T08:09:07.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9EE4AC97-FB07-4CC0-ADD8-E52DB261572F",
"versionEndExcluding": "1.7.0.829",
"versionStartIncluding": "1.7.0"
},
{
"criteria": "cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADD853AD-F4FD-44E5-8856-8618807A4769",
"versionEndExcluding": "1.8.0.888",
"versionStartIncluding": "1.8.0"
},
{
"criteria": "cpe:2.3:o:qnap:qts:*:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8AC9ED9-D346-46F1-B97F-E8CC259F3DA9",
"versionEndExcluding": "4.5.4.2957",
"versionStartIncluding": "4.5.1"
},
{
"criteria": "cpe:2.3:o:qnap:quts_hero:*:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E191F9BB-C20F-4A86-A7B4-8BB55FBB7B53",
"versionEndExcluding": "h4.5.4.2476",
"versionStartIncluding": "h4.5.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}