CVE-2021-28805

Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.3 build 20210505 on QSW-M2108-2C; versions prior to 1.0.3 build 20210505 on QSW-M2108-2S; versions prior to 1.0.3 build 20210505 on QSW-M2108R-2C; versions prior to 1.0.12 build 20210506 on QSW-M408.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:qnap:qss:*:*:*:*:*:*:*:*
OR cpe:2.3:h:qnap:qsw-m2108-2c:-:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m2108-2s:-:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m2108r-2c:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:qnap:qss:*:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m408:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://www.qnap.com/zh-tw/security-advisory/qsa-21-24 - Vendor Advisory () https://www.qnap.com/zh-tw/security-advisory/qsa-21-24 - Vendor Advisory
CVSS v2 : 2.1
v3 : 5.5
v2 : 2.1
v3 : 7.8

23 Jun 2021, 15:44

Type Values Removed Values Added
CWE CWE-200
References (MISC) https://www.qnap.com/zh-tw/security-advisory/qsa-21-24 - (MISC) https://www.qnap.com/zh-tw/security-advisory/qsa-21-24 - Vendor Advisory
CPE cpe:2.3:h:qnap:qsw-m2108-2c:-:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m408:-:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m2108r-2c:-:*:*:*:*:*:*:*
cpe:2.3:h:qnap:qsw-m2108-2s:-:*:*:*:*:*:*:*
cpe:2.3:a:qnap:qss:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5

11 Jun 2021, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-11 07:15

Updated : 2024-11-21 06:00


NVD link : CVE-2021-28805

Mitre link : CVE-2021-28805

CVE.ORG link : CVE-2021-28805


JSON object : View

Products Affected

qnap

  • qsw-m2108r-2c
  • qsw-m2108-2c
  • qss
  • qsw-m2108-2s
  • qsw-m408
CWE
CWE-540

Inclusion of Sensitive Information in Source Code

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor