7.5

CVE-2021-26620

IPTIME NAS2dual improper authentication vulnerability

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iptime ≫ Nas101 Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas101 Version -
Iptime ≫ Nas1dual Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas1dual Version -
Iptime ≫ Nas2dual Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas2dual Version -
Iptime ≫ Nas3 Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas3 Version -
Iptime ≫ Nas4 Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas4 Version -
Iptime ≫ Nas4dual Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas4dual Version -
Iptime ≫ Nas-i Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas-i Version -
Iptime ≫ Nas-ii Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas-ii Version -
Iptime ≫ Nas-iie Firmware SwPlatform windows Version < 1.4.82
   Iptime ≫ Nas-iie Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.69
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
krcert 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578
Third Party Advisory