CVE-2021-44056
Estado: ModificadaCrítica (9.8)—
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.93%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-44056",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "Video Station",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.5.9",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.3.13",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.1.8",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-05-05T17:15:10.453",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-22-14",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-22-14",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later"
},
{
"lang": "es",
"value": "Se ha informado de una vulnerabilidad de autenticación inapropiada que afecta al dispositivo QNAP que ejecuta Video Station. Si es explotada, esta vulnerabilidad permite a atacantes comprometer la seguridad del sistema. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de Video Station: Video Station 5.5.9 y posteriores Video Station 5.3.13 y posteriores Video Station 5.1.8 y posteriores"
}
],
"lastModified": "2026-06-17T04:11:52.053",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B1BA79E-C71B-4B2D-B38D-A65DC3806AFF",
"versionEndExcluding": "5.1.8"
},
{
"criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00BC7664-9F03-4909-B4E5-95DCAC7869B1",
"versionEndExcluding": "5.3.13",
"versionStartIncluding": "5.2.0"
},
{
"criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1042A67-6E5E-4B9D-912F-51FEC70A30FB",
"versionEndExcluding": "5.5.9",
"versionStartIncluding": "5.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}