« Volver al listado

CVE-2021-28815

Estado: ModificadaMedia (4.9)—

Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28815",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@qnapsecurity.com.tw",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 1.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@qnapsecurity.com.tw",
      "affectedData": [
        {
          "vendor": "QNAP Systems Inc.",
          "product": "myQNAPcloud Link",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.2.21",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QTS 4.5.3"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "myQNAPcloud Link",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.2.21",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QuTS hero h4.5.2"
          ]
        },
        {
          "vendor": "QNAP Systems Inc.",
          "product": "myQNAPcloud Link",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.2.21",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "QuTScloud c4.5.4"
          ]
        }
      ]
    }
  ],
  "published": "2021-06-16T04:15:08.530",
  "references": [
    {
      "url": "https://www.qnap.com/zh-tw/security-advisory/qsa-21-26",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@qnapsecurity.com.tw"
    },
    {
      "url": "https://www.qnap.com/zh-tw/security-advisory/qsa-21-26",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@qnapsecurity.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-922"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4."
    },
    {
      "lang": "es",
      "value": "Se ha reportado de que el almacenamiento no seguro de información confidencial afecta a los NAS de QNAP que ejecutan myQNAPcloud Link. Si es explotado, esta vulnerabilidad permite a atacantes remotos leer información confidencial accediendo al mecanismo de almacenamiento sin restricciones. Este problema afecta a: Versiones de myQNAPcloud Link de QNAP Systems Inc. anteriores a 2.2.21 en QTS versiones 4.5.3; versiones anteriores a 2.2.21 en QuTS hero versiones h4.5.2; versiones anteriores a 2.2.21 en QuTScloud  versiones c4.5.4"
    }
  ],
  "lastModified": "2026-06-17T03:46:54.917",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qnap:myqnapcloud_link:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FD423D3-82BD-40C5-9023-08A9DD66AACB",
              "versionEndExcluding": "2.2.21"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qnap:qts:4.5.3:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2F4E5174-441F-4ABA-8D4F-5040E99AEBA0"
            },
            {
              "criteria": "cpe:2.3:o:qnap:quts_hero:h4.5.2:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D8ED5973-0C2C-44ED-8A9C-4669C46F00BA"
            },
            {
              "criteria": "cpe:2.3:o:qnap:qutscloud:c4.5.4:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2E83E97A-D58A-44E2-A2EA-8159836A5AFE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@qnapsecurity.com.tw"
}