PT-2021-5431 · Qnap · Qnap Qvr
Jpcert/Cc
·
Published
2021-11-26
·
Updated
2021-12-02
·
CVE-2021-38685
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QNAP QVR versions prior to 5.1.6 build 20211109
Description
A command injection issue affects QNAP QVR, related to the failure to neutralize special elements used in an OS command. This allows a remote attacker to execute arbitrary commands. The vulnerability can be exploited by remote attackers to run arbitrary commands.
Recommendations
For QNAP QVR versions prior to 5.1.6 build 20211109, update to QVR FW 5.1.6 build 20211109 or later to resolve the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnap Qvr