7.5

CVE-2021-26620

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IptimeNas101 Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas101 Version-
IptimeNas1dual Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas1dual Version-
IptimeNas2dual Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas2dual Version-
IptimeNas3 Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas3 Version-
IptimeNas4 Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas4 Version-
IptimeNas4dual Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas4dual Version-
IptimeNas-i Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas-i Version-
IptimeNas-ii Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas-ii Version-
IptimeNas-iie Firmware SwPlatformwindows Version < 1.4.82
   IptimeNas-iie Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.689
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
vuln@krcert.or.kr 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.