CVE-2021-34344
Estado: ModificadaCrítica (9.8)—
A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 5.0: QUSBCam2 2.0.1 ( 2021/08/03 ) and later QTS 4.3.6: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 4.3.3: QUSBCam2 1.1.4 ( 2021/08/06 ) and later QuTS hero 4.5.3: QUSBCam2 1.1.4 ( 2021/07/30 ) and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.58%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-787
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-34344",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "QUSBCam2",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.4 ( 2021/07/30 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.5.4"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QUSBCam2",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.0.1 ( 2021/08/03 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 5.0"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QUSBCam2",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.4 ( 2021/07/30 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.6"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QUSBCam2",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.4 ( 2021/08/06 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.3"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QUSBCam2",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.1.4 ( 2021/07/30 )",
"versionType": "custom"
}
],
"platforms": [
"QuTS hero 4.5.3"
]
}
]
}
],
"published": "2021-09-10T04:15:18.343",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-34",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-34",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 5.0: QUSBCam2 2.0.1 ( 2021/08/03 ) and later QTS 4.3.6: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 4.3.3: QUSBCam2 1.1.4 ( 2021/08/06 ) and later QuTS hero 4.5.3: QUSBCam2 1.1.4 ( 2021/07/30 ) and later"
},
{
"lang": "es",
"value": "Se ha reportado de una vulnerabilidad de desbordamiento del búfer de la pila que afecta al dispositivo QNAP que ejecuta QUSBCam2. Si es explotado, esta vulnerabilidad permite a atacantes ejecutar código arbitrario. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 (30/07/2021) y posteriores QTS 5.0: QUSBCam2 2.0.1 (03/08/2021) y posteriores QTS 4.3.6: QUSBCam2 1.1.4 (30/07/2021) y posteriores QTS 4.3.3: QUSBCam2 1.1.4 ( 06/08/2021) y posteriores QuTS hero 4.5.3: QUSBCam2 1.1.4 (30/07/2021) y posteriores\n"
}
],
"lastModified": "2026-06-17T03:55:41.653",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qusbcam2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "410BC516-686F-4EA4-96AE-CE1A7BEE99A1",
"versionEndExcluding": "1.1.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FE9FAC96-AA2A-4CA5-A170-8C0E6BD47391"
},
{
"criteria": "cpe:2.3:o:qnap:qts:4.5.4:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4614DB45-E510-42A3-B254-DB8C4A99E907"
},
{
"criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.3:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FE1BC205-A042-417C-80BA-B1A1B24A689F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}