CVE-2021-38687
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.28%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-38687",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "Surveillance Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.2.0.4.2 ( 2021/10/26 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 5.0 (64 bit)"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Surveillance Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.2.0.3.2 ( 2021/10/26 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 5.0 (32 bit)"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Surveillance Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.1.5.4.6 ( 2021/10/26 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.6 (64 bit)"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Surveillance Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.1.5.3.6 ( 2021/10/26 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.6 (32 bit)"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "Surveillance Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.1.5.3.6 ( 2021/10/26 )",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.3"
]
}
]
}
],
"published": "2021-12-29T13:15:08.033",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-46",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-46",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later"
},
{
"lang": "es",
"value": "Se ha informado de una vulnerabilidad de desbordamiento del búfer de la pila que afecta al NAS de QNAP que ejecuta Surveillance Station. Si es explotado, esta vulnerabilidad permite a atacantes ejecutar código arbitrario. Ya hemos solucionado esta vulnerabilidad en las siguientes versiones de Surveillance Station: QTS versiones 5.0.0 (64 bits): Surveillance Station versiones 5.2.0.4.2 (26/10/2021) y posteriores QTS versiones 5.0.0 (32 bits): Surveillance Station versiones 5.2.0.3.2 (26/10/2021) y posteriores QTS versiones 4.3.6 (64 bits): Surveillance Station versiones 5.1.5.4.6 (26/10/2021) y posteriores QTS versiones 4.3.6 (32 bits): Surveillance Station versiones 5.1.5.3.6 (26/10/2021) y posteriores QTS versiones 4.3.3: Surveillance Station versiones 5.1.5.3.6 (26/10/2021) y posteriores"
}
],
"lastModified": "2026-06-17T04:02:35.407",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15A2CF32-14E5-45BF-A43B-2FE3768390FE",
"versionEndExcluding": "5.2.0.4.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:5.0.0:*:*:*:*:*:x64:*",
"vulnerable": false,
"matchCriteriaId": "E62D198C-6022-48F5-AD92-BB87D2D25342"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4FF03B3-0317-482D-B3AF-36B0BB8F5A53",
"versionEndExcluding": "5.2.0.3.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:5.0.0:*:*:*:*:*:x86:*",
"vulnerable": false,
"matchCriteriaId": "7536196C-B372-4437-82DF-369B14E3C52C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FCA8E47-638B-4318-8BBB-ED1EC7D7490C",
"versionEndExcluding": "5.1.5.4.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:x64:*",
"vulnerable": false,
"matchCriteriaId": "DC0A8856-836E-4096-A7F4-2AFC4D4763BD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66A2AC61-B545-4EA7-A7E4-2A2263E47C4A",
"versionEndExcluding": "5.1.5.3.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:x86:*",
"vulnerable": false,
"matchCriteriaId": "64340B53-0403-4EA7-9397-2D1C5882DF18"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66A2AC61-B545-4EA7-A7E4-2A2263E47C4A",
"versionEndExcluding": "5.1.5.3.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C5994C07-17FE-4784-9FA4-9675BA8B4743"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}