A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.
We have already fixed the vulnerability in the following versions:
QVPN Device Client for Mac 2.2.5 and later
Qsync for Mac 5.1.3 and later
Qfinder Pro Mac 7.11.1 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-51 |
|
History
Fri, 07 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later | |
| Title | QVPN Device Client, Qsync, Qfinder Pro | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2025-03-07T16:13:36.014Z
Updated: 2025-03-07T17:55:30.126Z
Reserved: 2024-11-22T06:21:49.206Z
Link: CVE-2024-53694
Updated: 2025-03-07T17:55:26.207Z
Status : Received
Published: 2025-03-07T17:15:20.103
Modified: 2025-03-07T17:15:20.103
Link: CVE-2024-53694
No data.