CVE-2021-28813 – Insufficiently Protected Credentials Vulnerability in QSW-M2116P-2T2S and QuNetSwitch
https://notcve.org/view.php?id=CVE-2021-28813
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later Se ha reportado de una vulnerabilidad que implica el almacenamiento no seguro de información confidencial que afecta al QSW-M2116P-2T2S y a los switches de QNAP que ejecutan QuNetSwitch. Si es explotado, esta vulnerabilidad permite a atacantes remotos leer información confidencial accediendo al mecanismo de almacenamiento sin restricciones. Ya hemos corregido esta vulnerabilidad en las siguientes versiones: QSW-M2116P-2T2S 1.0.6 build 210713 y posteriores QGD-1600P: QuNetSwitch 1.0.6.1509 y posteriores QGD-1602P: QuNetSwitch 1.0.6.1509 y posteriores QGD-3014PT: QuNetSwitch 1.0.6.1519 y posteriores • https://www.qnap.com/en/security-advisory/qsa-21-37 • CWE-259: Use of Hard-coded Password CWE-522: Insufficiently Protected Credentials CWE-798: Use of Hard-coded Credentials CWE-922: Insecure Storage of Sensitive Information •