CVE-2021-28815
Estado: ModificadaMedia (4.9)—
Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 4.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.73%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-922
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-28815",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "myQNAPcloud Link",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.2.21",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.5.3"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "myQNAPcloud Link",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.2.21",
"versionType": "custom"
}
],
"platforms": [
"QuTS hero h4.5.2"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "myQNAPcloud Link",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.2.21",
"versionType": "custom"
}
],
"platforms": [
"QuTScloud c4.5.4"
]
}
]
}
],
"published": "2021-06-16T04:15:08.530",
"references": [
{
"url": "https://www.qnap.com/zh-tw/security-advisory/qsa-21-26",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/zh-tw/security-advisory/qsa-21-26",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4."
},
{
"lang": "es",
"value": "Se ha reportado de que el almacenamiento no seguro de información confidencial afecta a los NAS de QNAP que ejecutan myQNAPcloud Link. Si es explotado, esta vulnerabilidad permite a atacantes remotos leer información confidencial accediendo al mecanismo de almacenamiento sin restricciones. Este problema afecta a: Versiones de myQNAPcloud Link de QNAP Systems Inc. anteriores a 2.2.21 en QTS versiones 4.5.3; versiones anteriores a 2.2.21 en QuTS hero versiones h4.5.2; versiones anteriores a 2.2.21 en QuTScloud versiones c4.5.4"
}
],
"lastModified": "2026-06-17T03:46:54.917",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:myqnapcloud_link:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FD423D3-82BD-40C5-9023-08A9DD66AACB",
"versionEndExcluding": "2.2.21"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.5.3:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2F4E5174-441F-4ABA-8D4F-5040E99AEBA0"
},
{
"criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.2:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8ED5973-0C2C-44ED-8A9C-4669C46F00BA"
},
{
"criteria": "cpe:2.3:o:qnap:qutscloud:c4.5.4:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2E83E97A-D58A-44E2-A2EA-8159836A5AFE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}