10
CVE-2021-44056
- EPSS 0.18%
- Veröffentlicht 05.05.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:30:19
- Quelle security@qnapsecurity.com.tw
- Teams Watchlist Login
- Unerledigt Login
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Video Station Version < 5.1.8
Qnap ≫ Video Station Version >= 5.2.0 < 5.3.13
Qnap ≫ Video Station Version >= 5.4.0 < 5.5.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.18% | 0.398 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
security@qnapsecurity.com.tw | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.