CVE-2021-26620
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Affected (9)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas101 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas1dual | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas2dual | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas3 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas4 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas4dual | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas I | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas Ii | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.82 |
| Running on/with | Platform Versions |
|---|---|
Iptime Nas Iie | All versions |
References (2)
Source: vuln@krcert.or.kr
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.