A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)
2020-12-31T17:15:12.320
2024-11-21T03:58:51.163
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | qnap | qts | < 4.5.1.1456 | Yes |
Operating System | qnap | quts_hero | < h4.5.1.1472 | Yes |
Operating System | qnap | qutscloud | < c4.5.2.1379 | Yes |