Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-34343


A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210701 and later QuTScloud c4.5.6.1755 and later QuTS hero h4.5.4.1771 build 20210825 and later


Published

2021-09-10T04:15:18.073

Last Modified

2024-11-21T06:10:12.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-787
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qnap qts < 4.3.3.1693 Yes
Operating System qnap qts < 4.3.6.1750 Yes
Operating System qnap qts < 4.5.4.1715 Yes
Operating System qnap qts < 5.0.0.1716 Yes
Operating System qnap quts_hero < h4.5.4.1771 Yes
Operating System qnap qutscloud < c4.5.6.1755 Yes

References