← Back to CVE List
Vulnerability Intelligence Report
Insecure Storage of Sensitive Information in myQNAPcloud Link

CVE-2021-28815

Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.

No Active Exploit Signals
CVSS Base Score
6.0
MEDIUM
Exploitability:1.5
Impact Score:4.0
EPSS Probability:1.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-922 ↗CWE-922 Insecure Storage of Sensitive Information

Affected Products & Versions

Vendor Product Affected Versions
QNAP Systems Inc. myQNAPcloud Link unspecified < 2.2.21 (affected)
QNAP Systems Inc. myQNAPcloud Link unspecified < 2.2.21 (affected)
QNAP Systems Inc. myQNAPcloud Link unspecified < 2.2.21 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.711%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityQNAP Systems, Inc. · Vendor · Taiwan
Reserved2021-03-18T00:00:00
Published2021-06-16T04:00:11
Patch Date2021-06-16
Last Updated2024-09-17T01:16:56

LINK COPIED TO CLIPBOARD