Vulnerability Intelligence Report
Insecure Storage of Sensitive Information in myQNAPcloud Link
CVE-2021-28815
Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.
No Active Exploit Signals
CVSS Base Score
6.0
MEDIUM
Exploitability:1.5
Impact Score:4.0
EPSS Probability:1.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-922 ↗CWE-922 Insecure Storage of Sensitive Information
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| QNAP Systems Inc. | myQNAPcloud Link | unspecified < 2.2.21 (affected) |
| QNAP Systems Inc. | myQNAPcloud Link | unspecified < 2.2.21 (affected) |
| QNAP Systems Inc. | myQNAPcloud Link | unspecified < 2.2.21 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.711%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | QNAP Systems, Inc. · Vendor · Taiwan |
| Reserved | 2021-03-18T00:00:00 |
| Published | 2021-06-16T04:00:11 |
| Patch Date | 2021-06-16 |
| Last Updated | 2024-09-17T01:16:56 |
Community Chatter & Buzz