A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.
We have already fixed the vulnerability in the following versions:
QVPN Device Client for Mac 2.2.5 and later
Qsync for Mac 5.1.3 and later
Qfinder Pro Mac 7.11.1 and later
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-24-51 |
![]() ![]() |
History
Fri, 07 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 07 Mar 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later | |
Title | QVPN Device Client, Qsync, Qfinder Pro | |
Weaknesses | CWE-367 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2025-03-07T17:55:30.126Z
Reserved: 2024-11-22T06:21:49.206Z
Link: CVE-2024-53694

Updated: 2025-03-07T17:55:26.207Z

Status : Received
Published: 2025-03-07T17:15:20.103
Modified: 2025-03-07T17:15:20.103
Link: CVE-2024-53694

No data.