Unprotected storage of credentials in QNAP Systems, Inc. products - CVE-2021-28815
Published: June 18, 2021
Vulnerability identifier: #VU54221
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28815
CWE-ID: CWE-256
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to insecure storage of sensitive information. A remote attacker can access the unrestricted storage mechanism to read sensitive information on the system.
Affected software
QuTScloud
QuTS hero
myQNAPcloud Link
QNAP QTS
QuTS hero
myQNAPcloud Link
QNAP QTS
How to mitigate CVE-2021-28815
Install updates from vendor's website.
QuTScloud - update to c4.5.4
QuTS hero - update to h4.5.2
myQNAPcloud Link - update to 2.2.21
QNAP QTS - update to 4.5.3
QuTS hero - update to h4.5.2
myQNAPcloud Link - update to 2.2.21
QNAP QTS - update to 4.5.3