Stack-based buffer overflow in QNAP Systems, Inc. products - CVE-2021-34343

 

Stack-based buffer overflow in QNAP Systems, Inc. products - CVE-2021-34343

Published: September 9, 2021


Vulnerability identifier: #VU56436
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34343
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote unauthenticated attacker can send a specially crafted request to trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

QNAP QTS
QuTScloud
QuTS hero

How to mitigate CVE-2021-34343

Install updates from vendor's website.

QNAP QTS - addressed in versions 4.3.3.1693 20210624, 4.3.6.1750 20210730, 5.0.0.1716 20210701
QuTScloud - update to c4.5.6.1755
QuTS hero - update to h4.5.4.1771 build 20210825

External References

Related Security Bulletins