Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28813


A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later


Published

2021-09-10T04:15:16.613

Last Modified

2024-11-21T06:00:15.093

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-259
    CWE-522
    CWE-798
  • Type: Primary
    CWE-922

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qnap qsw-m2116p-2t2s_firmware < 1.0.6 Yes
Hardware qnap qsw-m2116p-2t2s - No
Application qnap qunetswitch < 1.0.6.1509 Yes
Hardware qnap qgd-1600p - No
Hardware qnap qgd-1602p - No
Hardware qnap qgd-3014pt - No

References