« Volver al listado

CVE-2021-26620

Estado: ModificadaAlta (7.5)—

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (9)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-26620",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vuln@krcert.or.kr",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@krcert.or.kr",
      "affectedData": [
        {
          "vendor": "EFM Networks Co., Ltd",
          "product": "ipTIME NAS product (NAS1, 2, 3, 4, 1dual, 2dual 4dual)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.4.82",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ]
        }
      ]
    }
  ],
  "published": "2022-03-25T19:15:08.687",
  "references": [
    {
      "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vuln@krcert.or.kr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords."
    },
    {
      "lang": "es",
      "value": "Se ha detectado una vulnerabilidad de autenticación inapropiada conllevando a un filtrado de información en iptime NAS2dual. Los atacantes remotos son capaces de robar información importante en el servidor al explotar vulnerabilidades como la autenticación insuficiente cuando es accedida a la carpeta compartida y son cambiadas las contraseñas de usuarios"
    }
  ],
  "lastModified": "2026-06-17T03:43:34.660",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas101_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "884756F6-7AD4-4427-A354-7C9428716CB8",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas101:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B46EE9BB-2CA6-49E1-BB46-9621805C89A0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas1dual_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0851FBDB-7C72-4072-9EA4-905F69C36CBC",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas1dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2ACEC464-70B3-452B-A1A3-594C697E3AB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas2dual_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "047128B3-8F89-48F0-8982-3C51B6CFC769",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas2dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "271D21D5-A55E-4D4F-8473-5A7A67573DEA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas3_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD158E92-E69D-47E8-BABA-16933160E1FE",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "409E183B-5919-48FF-A121-EB89E58D1956"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas4_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE790ADF-B496-49CB-AF73-9612141DA38B",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas4:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5681FB7D-A7F5-48F1-AE10-79F5B64081E5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas4dual_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80AC9D9F-57CF-4BAC-8988-FCE44F53C4E8",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas4dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0429CC1A-B95C-4FB0-90D6-D6CAD8E1CC14"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas-i_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06940CF1-703F-44E6-9078-B2F1E64EA745",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas-i:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CBE26B68-CC6F-4ABE-818A-8872A0753DC6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas-ii_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78BDB206-048A-4D12-9AFC-36B06DFDD49F",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas-ii:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8C101E48-A4C0-418A-9FBD-AF6B9115B0A9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas-iie_firmware:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8410D8F2-D177-4A96-8BD4-F9A96ECE699A",
              "versionEndExcluding": "1.4.82"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas-iie:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6B6F0961-E444-4519-BC03-9BFADEDF73EE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vuln@krcert.or.kr"
}