Stack-based buffer overflow in QNAP Systems, Inc. products - CVE-2021-34343
Published: September 9, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote unauthenticated attacker can send a specially crafted request to trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
QuTScloud
QuTS hero
How to mitigate CVE-2021-34343
QuTScloud - update to c4.5.6.1755
QuTS hero - update to h4.5.4.1771 build 20210825