Description
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
No analysis available yet.
Remediation
Vendor Solution
We have already fixed this vulnerability in the following versions of QSW-M2116P-2T2S, QuNetSwitch: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15469 | A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-21-37 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-17T00:21:02.142Z
Reserved: 2021-03-18T00:00:00.000Z
Link: CVE-2021-28813
No data.
Status : Modified
Published: 2021-09-10T04:15:16.613
Modified: 2024-11-21T06:00:15.093
Link: CVE-2021-28813
No data.
OpenCVE Enrichment
No data.
EUVD