CVE-2021-34345
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later
Affected (14)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Ej1600 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R1620sdc | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R1620sep Rp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R1220sep Rp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl D1600s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl D800s | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl D400s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R1200s Rp | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R400s | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl R1200c Rp | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tl D800c | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tr 004 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tr 002 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 |
| Running on/with | Platform Versions |
|---|---|
Qnap Tr 004u | All versions |
References (2)
Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.