CVE-2021-28813
Estado: ModificadaAlta (7.5)—
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.09%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-259, CWE-522, CWE-798
- CWE-922
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-28813",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 6,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "QSW-M2116P-2T2S",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.0.6 build 210713",
"versionType": "custom"
}
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuNetSwitch",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.0.6.1509",
"versionType": "custom"
}
],
"platforms": [
"QGD-1600P"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuNetSwitch",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.0.6.1509",
"versionType": "custom"
}
],
"platforms": [
"QGD-1602P"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuNetSwitch",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.0.6.1519",
"versionType": "custom"
}
],
"platforms": [
"QGD-3014PT"
]
}
]
}
],
"published": "2021-09-10T04:15:16.613",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-37",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-37",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-259"
},
{
"lang": "en",
"value": "CWE-522"
},
{
"lang": "en",
"value": "CWE-798"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later"
},
{
"lang": "es",
"value": "Se ha reportado de una vulnerabilidad que implica el almacenamiento no seguro de información confidencial que afecta al QSW-M2116P-2T2S y a los switches de QNAP que ejecutan QuNetSwitch. Si es explotado, esta vulnerabilidad permite a atacantes remotos leer información confidencial accediendo al mecanismo de almacenamiento sin restricciones. Ya hemos corregido esta vulnerabilidad en las siguientes versiones: QSW-M2116P-2T2S 1.0.6 build 210713 y posteriores QGD-1600P: QuNetSwitch 1.0.6.1509 y posteriores QGD-1602P: QuNetSwitch 1.0.6.1509 y posteriores QGD-3014PT: QuNetSwitch 1.0.6.1519 y posteriores"
}
],
"lastModified": "2026-06-17T03:46:54.667",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qsw-m2116p-2t2s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67AD84CC-767C-4B79-BAA1-3970312DC03F",
"versionEndExcluding": "1.0.6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qnap:qsw-m2116p-2t2s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "86BB89DE-E848-4092-BE04-8B7560965FE6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qunetswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4EE33A84-65B1-4C70-9ED3-1CCBCD1FEDA0",
"versionEndExcluding": "1.0.6.1509"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qnap:qgd-1600p:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "07F5C68D-E3BB-4670-8325-6A33DC99AA62"
},
{
"criteria": "cpe:2.3:h:qnap:qgd-1602p:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "90A06542-12A0-4D2C-86F2-1003408C08E6"
},
{
"criteria": "cpe:2.3:h:qnap:qgd-3014pt:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FECC7C09-6554-4DAF-B487-2138C51A6BE8"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}