CVE-2021-28813
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
Published:Sep 10, 2021
Last Modified:Nov 21, 2024
EPS:Sep 10, 2021
EPSS Score:0.00375
CVSS Score:9.6
Affected Products
Vendor
Product
Action
Vendor
Qnap
Product
Qgd-1600p
Qnap
Qgd-1600p
Vendor
Qnap
Product
Qgd-1602p
Qnap
Qgd-1602p
Vendor
Qnap
Product
Qgd-3014pt
Qnap
Qgd-3014pt
Vendor
Qnap
Product
Qsw-m2116p-2t2s
Qnap
Qsw-m2116p-2t2s
Vendor
Qnap
Product
Qsw-m2116p-2t2s Firmware
Qnap
Qsw-m2116p-2t2s Firmware
Vendor
Qnap
Product
Qunetswitch
Qnap
Qunetswitch
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
