CERT-In Vulnerability Note
CIVN-2021-0385
Sensitive Information Exposure Vulnerability in QNAP QTS, QuTS hero, and QuTScloud
Original Issue Date:December 31, 2021
Severity Rating: MEDIUM
Systems Affected
- QTS prior to 4.5.4.1787 build 20210910
- QuTS hero prior to h4.5.4.1771 build 20210825
- QuTScloud prior to c4.5.7.1864
Overview
A Vulnerability has been reported in QNAP QTS, QuTS hero, and QuTScloud which could allow an attacker to obtain sensitive information on targeted systems.
Description
A Vulnerability exists in QNAP QTS, QuTS hero, and QuTScloud products involving exposure of sensitive information.
Successful exploitation of this vulnerability could allow an attacker to compromise the security of the targeted systems.
Solution
Apply appropriate updates as mentioned by vendor
https://www.qnap.com/en/security-advisory/qsa-21-53
Vendor Information
QNAP
https://www.qnap.com/en/security-advisory/qsa-21-53
References
QNAP
https://www.qnap.com/en/security-advisory/qsa-21-53
CVE Name
CVE-2021-34347
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|