« Volver al listado

CVE-2021-34360

Estado: ModificadaAlta (8.8)—

A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-34360",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "Proxy Server",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.4.2 ( 2021/12/30 )",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QTS 4.5.x"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "Proxy Server",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.4.3 ( 2022/01/18 )",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QuTS hero h5.0.0"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "Proxy Server",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.4.2 ( 2021/12/30 )",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QuTScloud c4.5.6"
          ]
        }
      ]
    }
  ],
  "published": "2022-05-26T14:15:07.883",
  "references": [
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-22-18",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/en/security-advisory/qsa-22-18",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later"
    },
    {
      "lang": "es",
      "value": "Se ha informado de una vulnerabilidad de tipo cross-site request forgery (CSRF) que afecta al dispositivo QNAP ejecutando Servidor Proxy. Si es explotado, esta vulnerabilidad permite a atacantes remotos inyectar código malicioso. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) y posteriores QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores"
    }
  ],
  "lastModified": "2026-06-17T03:55:43.170",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E63E7A5-549B-456D-A67C-9742BC0A32D3",
              "versionEndExcluding": "1.4.2",
              "versionStartIncluding": "1.4.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "36C84C4C-AAE2-4AC5-A723-64271BBB91A5",
              "versionEndIncluding": "4.5.4.2012",
              "versionStartIncluding": "4.5.1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3D1B231-C82A-476E-A147-1B2FE9DD6A62",
              "versionEndExcluding": "1.4.3",
              "versionStartIncluding": "1.4.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h5.0.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "79F492BF-8B5C-4C3A-9F00-D3304BFED992"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:nas_proxy_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E63E7A5-549B-456D-A67C-9742BC0A32D3",
              "versionEndExcluding": "1.4.2",
              "versionStartIncluding": "1.4.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qutscloud:c4.5.6:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1BE7A673-8EAC-4B2C-927A-9B10F3F55FE2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}