CVE-2021-34360
Estado: ModificadaAlta (8.8)—
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
- CWE-352
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-34360",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "Proxy Server",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.4.2 ( 2021/12/30 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.5.x"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Proxy Server",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.4.3 ( 2022/01/18 )",
"versionType": "custom"
}
],
"platforms": [
"QuTS hero h5.0.0"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Proxy Server",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.4.2 ( 2021/12/30 )",
"versionType": "custom"
}
],
"platforms": [
"QuTScloud c4.5.6"
]
}
]
}
],
"published": "2022-05-26T14:15:07.883",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-22-18",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-22-18",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later"
},
{
"lang": "es",
"value": "Se ha informado de una vulnerabilidad de tipo cross-site request forgery (CSRF) que afecta al dispositivo QNAP ejecutando Servidor Proxy. Si es explotado, esta vulnerabilidad permite a atacantes remotos inyectar código malicioso. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) y posteriores QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores"
}
],
"lastModified": "2026-06-17T03:55:43.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E63E7A5-549B-456D-A67C-9742BC0A32D3",
"versionEndExcluding": "1.4.2",
"versionStartIncluding": "1.4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "36C84C4C-AAE2-4AC5-A723-64271BBB91A5",
"versionEndIncluding": "4.5.4.2012",
"versionStartIncluding": "4.5.1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3D1B231-C82A-476E-A147-1B2FE9DD6A62",
"versionEndExcluding": "1.4.3",
"versionStartIncluding": "1.4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:quts_hero:h5.0.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "79F492BF-8B5C-4C3A-9F00-D3304BFED992"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E63E7A5-549B-456D-A67C-9742BC0A32D3",
"versionEndExcluding": "1.4.2",
"versionStartIncluding": "1.4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qutscloud:c4.5.6:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1BE7A673-8EAC-4B2C-927A-9B10F3F55FE2"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}