PT-2021-17925 · Qnap Systems · Qsw-M2108R-2C+2

Qian Chen

·

Published

2021-06-11

·

Updated

2021-06-23

·

CVE-2021-28801

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2C QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2S QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108R-2C
Description: An out-of-bounds read issue has been reported to affect certain QNAP switches running QSS. If exploited, this issue allows attackers to read sensitive information on the system.
Recommendations: For QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2C, update to version 1.0.2 build 20210122 or later. For QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2S, update to version 1.0.2 build 20210122 or later. For QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108R-2C, update to version 1.0.2 build 20210122 or later.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28801

Affected Products

Qss
Qsw-M2108R-2C
Qsw-M2108-2S