An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
References
Link | Resource |
---|---|
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578 | Third Party Advisory |
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 05:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578 - Third Party Advisory |
31 Mar 2022, 14:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:iptime:nas2dual_firmware:*:*:*:*:*:windows:*:* cpe:2.3:h:iptime:nas4dual:-:*:*:*:*:*:*:* cpe:2.3:o:iptime:nas-iie_firmware:*:*:*:*:*:windows:*:* cpe:2.3:h:iptime:nas-ii:-:*:*:*:*:*:*:* cpe:2.3:h:iptime:nas2dual:-:*:*:*:*:*:*:* cpe:2.3:h:iptime:nas-i:-:*:*:*:*:*:*:* cpe:2.3:o:iptime:nas4_firmware:*:*:*:*:*:windows:*:* cpe:2.3:o:iptime:nas101_firmware:*:*:*:*:*:windows:*:* cpe:2.3:o:iptime:nas1dual_firmware:*:*:*:*:*:windows:*:* cpe:2.3:o:iptime:nas3_firmware:*:*:*:*:*:windows:*:* cpe:2.3:h:iptime:nas-iie:-:*:*:*:*:*:*:* cpe:2.3:o:iptime:nas-i_firmware:*:*:*:*:*:windows:*:* cpe:2.3:h:iptime:nas4:-:*:*:*:*:*:*:* cpe:2.3:h:iptime:nas3:-:*:*:*:*:*:*:* cpe:2.3:o:iptime:nas4dual_firmware:*:*:*:*:*:windows:*:* cpe:2.3:h:iptime:nas101:-:*:*:*:*:*:*:* cpe:2.3:h:iptime:nas1dual:-:*:*:*:*:*:*:* cpe:2.3:o:iptime:nas-ii_firmware:*:*:*:*:*:windows:*:* |
|
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
References | (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578 - Third Party Advisory |
25 Mar 2022, 19:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-25 19:15
Updated : 2024-11-21 05:56
NVD link : CVE-2021-26620
Mitre link : CVE-2021-26620
CVE.ORG link : CVE-2021-26620
JSON object : View
Products Affected
iptime
- nas1dual
- nas101_firmware
- nas4_firmware
- nas101
- nas3_firmware
- nas4dual_firmware
- nas-ii
- nas-iie_firmware
- nas4
- nas3
- nas-iie
- nas2dual_firmware
- nas1dual_firmware
- nas2dual
- nas-ii_firmware
- nas4dual
- nas-i
- nas-i_firmware
CWE
CWE-287
Improper Authentication