{"id":"CVE-2024-38639","title":"An improper authentication vulnerability has been reported to affect product","summary":"An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-287"],"vendor":"QNAP Systems Inc.","product":"QTS","affected":["QTS"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:29:56.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-38639","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-24-37","label":"security@qnapsecurity.com.tw"}],"tags":["nvd","cve.org"],"epss":0.00246,"epssPercentile":0.1609,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T14:15:06.086803Z"},"ingestedAt":"2026-09-18T07:37:23.429Z","slug":"CVE-2024-38639","body":"## Overview\n\nAn improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.\nQTS is not affected.\n\nWe have already fixed the vulnerability in the following version:\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}