7.5
CVE-2021-26620
- EPSS 1.35%
- Veröffentlicht 25.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:36
- Erkennungen
IPTIME NAS2dual improper authentication vulnerability
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iptime ≫ Nas101 Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas1dual Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas2dual Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas3 Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas4 Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas4dual Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas-i Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas-ii Firmware SwPlatform windows Version < 1.4.82
Iptime ≫ Nas-iie Firmware SwPlatform windows Version < 1.4.82
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| krcert | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66578