10
CVE-2021-44057
- EPSS 0.35%
- Veröffentlicht 05.05.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:30:19
- Quelle security@qnapsecurity.com.tw
- Teams Watchlist Login
- Unerledigt Login
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Photo Station Version < 5.4.13
Qnap ≫ Photo Station Version >= 5.6.0 < 5.7.16
Qnap ≫ Photo Station Version >= 6.0.0 < 6.0.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.35% | 0.568 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
security@qnapsecurity.com.tw | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.