A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later

Project Subscriptions

Vendors Products
Qgd-1600p Subscribe
Qgd-1602p Subscribe
Qgd-3014pt Subscribe
Qsw-m2116p-2t2s Subscribe
Qsw-m2116p-2t2s Firmware Subscribe
Qunetswitch Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-15469 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
Fixes

Solution

We have already fixed this vulnerability in the following versions of QSW-M2116P-2T2S, QuNetSwitch: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2024-09-17T00:21:02.142Z

Reserved: 2021-03-18T00:00:00

Link: CVE-2021-28813

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-10T04:15:16.613

Modified: 2024-11-21T06:00:15.093

Link: CVE-2021-28813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.