Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-21-26 | Vendor Advisory | 
| https://www.qnap.com/zh-tw/security-advisory/qsa-21-26 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 06:00
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : 4.0 v3 : 6.0 | 
| References | () https://www.qnap.com/zh-tw/security-advisory/qsa-21-26 - Vendor Advisory | 
23 Jun 2021, 19:40
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : 4.0 v3 : 4.9 | 
| CPE | cpe:2.3:o:qnap:qutscloud:c4.5.4:-:*:*:*:*:*:* cpe:2.3:a:qnap:myqnapcloud_link:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:h4.5.2:-:*:*:*:*:*:* cpe:2.3:o:qnap:qts:4.5.3:-:*:*:*:*:*:* | |
| References | (CONFIRM) https://www.qnap.com/zh-tw/security-advisory/qsa-21-26 - Vendor Advisory | 
16 Jun 2021, 05:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-922 | |
| Summary | Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4. | 
16 Jun 2021, 04:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-06-16 04:15
Updated : 2024-11-21 06:00
NVD link : CVE-2021-28815
Mitre link : CVE-2021-28815
CVE.ORG link : CVE-2021-28815
JSON object : View
Products Affected
                qnap
- qutscloud
- qts
- myqnapcloud_link
- quts_hero
CWE
                
                    
                        
                        CWE-922
                        
            Insecure Storage of Sensitive Information
