CVE-2021-28813
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
Affected (2)
Products: Qnap: Qsw M2116p 2t2s Firmware, Qunetswitch
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Qsw M2116p 2t2s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6.1509 |
| Running on/with | Platform Versions |
|---|---|
Qnap Qgd 1600p | All versions |
Qnap Qgd 1602p | All versions |
Qnap Qgd 3014pt | All versions |
Related CWEs
CWE-259
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
CWE-522
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-798
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-922
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
References (2)
Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.