TROYANOSYVIRUS
Back to CVEs

CVE-2021-28801

LOW
3.1

Description

An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read sensitive information on the system. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2C; versions prior to 1.0.2 build 20210122 on QSW-M2108-2S; versions prior to 1.0.2 build 20210122 on QSW-M2108R-2C.

CVE Details

CVSS v3.1 Score3.1
SeverityLOW
CVSS VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack VectorADJACENT_NETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published6/11/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

qnap:qssqnap:qsw-m2108-2cqnap:qsw-m2108-2sqnap:qsw-m2108r-2c

Weaknesses (CWE)

CWE-125

References

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.