« Volver al listado

CVE-2021-28813

Estado: ModificadaAlta (7.5)—

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28813",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QSW-M2116P-2T2S",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.0.6 build 210713",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuNetSwitch",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.0.6.1509",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QGD-1600P"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuNetSwitch",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.0.6.1509",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QGD-1602P"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "QuNetSwitch",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.0.6.1519",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QGD-3014PT"
          ]
        }
      ]
    }
  ],
  "published": "2021-09-10T04:15:16.613",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-21-37",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-21-37",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-259"
        },
        {
          "lang": "en",
          "value": "CWE-522"
        },
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-922"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later"
    },
    {
      "lang": "es",
      "value": "Se ha reportado de una vulnerabilidad que implica el almacenamiento no seguro de información confidencial que afecta al QSW-M2116P-2T2S y a los switches de QNAP que ejecutan QuNetSwitch. Si es explotado, esta vulnerabilidad permite a atacantes remotos leer información confidencial accediendo al mecanismo de almacenamiento sin restricciones. Ya hemos corregido esta vulnerabilidad en las siguientes versiones: QSW-M2116P-2T2S 1.0.6 build 210713 y posteriores QGD-1600P: QuNetSwitch 1.0.6.1509 y posteriores QGD-1602P: QuNetSwitch 1.0.6.1509 y posteriores QGD-3014PT: QuNetSwitch 1.0.6.1519 y posteriores"
    }
  ],
  "lastModified": "2026-06-17T03:46:54.667",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qsw-m2116p-2t2s_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67AD84CC-767C-4B79-BAA1-3970312DC03F",
              "versionEndExcluding": "1.0.6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:qsw-m2116p-2t2s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "86BB89DE-E848-4092-BE04-8B7560965FE6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:qunetswitch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EE33A84-65B1-4C70-9ED3-1CCBCD1FEDA0",
              "versionEndExcluding": "1.0.6.1509"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qnap:qgd-1600p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "07F5C68D-E3BB-4670-8325-6A33DC99AA62"
            },
            {
              "criteria": "cpe:2.3:h:qnap:qgd-1602p:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "90A06542-12A0-4D2C-86F2-1003408C08E6"
            },
            {
              "criteria": "cpe:2.3:h:qnap:qgd-3014pt:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FECC7C09-6554-4DAF-B487-2138C51A6BE8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}