« Volver al listado

CVE-2021-20713

Estado: ModificadaAlta (7.8)—

Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the product's Windows client is installed to gain administrative privileges via unspecified vectors. As a result, sensitive information may be altered/obtained or unintended operations may be performed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20713",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "QualitySoft Corporation",
          "product": "QND Advance/Premium/Standard",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.11.0.4i and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-24T04:15:11.433",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN74686032/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.qualitysoft.com/product/qnd_vulnerabilities_2021/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN74686032/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.qualitysoft.com/product/qnd_vulnerabilities_2021/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the product's Windows client is installed to gain administrative privileges via unspecified vectors. As a result, sensitive information may be altered/obtained or unintended operations may be performed."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de  escalada de privilegios en QND Advance/Premium/Standard Ver.11.0.4i y anteriores, permite a un atacante que pueda iniciar sesión en la PC donde está instalado el cliente Windows del producto obtener privilegios administrativos por medio de vectores no especificados. Como resultado, se puede alterar y obtener información confidencial o se pueden lleva a cabo operaciones no deseadas"
    }
  ],
  "lastModified": "2026-06-17T03:34:18.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qualitysoft:qnd:*:*:*:*:advance:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90CDA95B-8288-4274-A523-1CBE56740651",
              "versionEndIncluding": "11.0.4i"
            },
            {
              "criteria": "cpe:2.3:a:qualitysoft:qnd:*:*:*:*:premium:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1AEE97C-7915-4138-B12B-3806C62F77B8",
              "versionEndIncluding": "11.0.4i"
            },
            {
              "criteria": "cpe:2.3:a:qualitysoft:qnd:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCA7169D-9F69-4796-9A6F-3779D0BCE6C9",
              "versionEndIncluding": "11.0.4i"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}