CVE Database
/

CVE-2021-28813

Back to search

CVE-2021-28813

Published: Sep 10, 2021

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.1

9.6

CRITICAL

Description

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later

VendorProductVersions

QNAP Systems Inc.

QSW-M2116P-2T2S

affected
unspecified - < 1.0.6 build 210713

QNAP Systems Inc.

QuNetSwitch

affected
unspecified - < 1.0.6.1509

QNAP Systems Inc.

QuNetSwitch

affected
unspecified - < 1.0.6.1509

QNAP Systems Inc.

QuNetSwitch

affected
unspecified - < 1.0.6.1519

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now