// For flags

CVE-2021-34345

Stack Based Overflow Vulnerability in NVR Storage Expansion

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later

Se ha reportado de una vulnerabilidad de desbordamiento del búfer de la pila que afecta al dispositivo QNAP que ejecuta NVR Storage Expansion. Si es explotado, esta vulnerabilidad permite a atacantes ejecutar código arbitrario. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) y posteriores

*Credits: crixer
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-08 CVE Reserved
  • 2021-09-10 CVE Published
  • 2024-08-16 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qnap
Search vendor "Qnap"
Ej1600 Firmware
Search vendor "Qnap" for product "Ej1600 Firmware"
< 1.0.6
Search vendor "Qnap" for product "Ej1600 Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Ej1600
Search vendor "Qnap" for product "Ej1600"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r1620sdc Firmware
Search vendor "Qnap" for product "Tl-r1620sdc Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r1620sdc Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r1620sdc
Search vendor "Qnap" for product "Tl-r1620sdc"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r1620sep-rp Firmware
Search vendor "Qnap" for product "Tl-r1620sep-rp Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r1620sep-rp Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r1620sep-rp
Search vendor "Qnap" for product "Tl-r1620sep-rp"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r1220sep-rp Firmware
Search vendor "Qnap" for product "Tl-r1220sep-rp Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r1220sep-rp Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r1220sep-rp
Search vendor "Qnap" for product "Tl-r1220sep-rp"
--
Safe
Qnap
Search vendor "Qnap"
Tl-d1600s Firmware
Search vendor "Qnap" for product "Tl-d1600s Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-d1600s Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-d1600s
Search vendor "Qnap" for product "Tl-d1600s"
--
Safe
Qnap
Search vendor "Qnap"
Tl-d800s Firmware
Search vendor "Qnap" for product "Tl-d800s Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-d800s Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-d800s
Search vendor "Qnap" for product "Tl-d800s"
--
Safe
Qnap
Search vendor "Qnap"
Tl-d400s Firmware
Search vendor "Qnap" for product "Tl-d400s Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-d400s Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-d400s
Search vendor "Qnap" for product "Tl-d400s"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r1200s-rp Firmware
Search vendor "Qnap" for product "Tl-r1200s-rp Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r1200s-rp Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r1200s-rp
Search vendor "Qnap" for product "Tl-r1200s-rp"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r400s Firmware
Search vendor "Qnap" for product "Tl-r400s Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r400s Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r400s
Search vendor "Qnap" for product "Tl-r400s"
--
Safe
Qnap
Search vendor "Qnap"
Tl-r1200c-rp Firmware
Search vendor "Qnap" for product "Tl-r1200c-rp Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-r1200c-rp Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-r1200c-rp
Search vendor "Qnap" for product "Tl-r1200c-rp"
--
Safe
Qnap
Search vendor "Qnap"
Tl-d800c Firmware
Search vendor "Qnap" for product "Tl-d800c Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tl-d800c Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tl-d800c
Search vendor "Qnap" for product "Tl-d800c"
--
Safe
Qnap
Search vendor "Qnap"
Tr-004 Firmware
Search vendor "Qnap" for product "Tr-004 Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tr-004 Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tr-004
Search vendor "Qnap" for product "Tr-004"
--
Safe
Qnap
Search vendor "Qnap"
Tr-002 Firmware
Search vendor "Qnap" for product "Tr-002 Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tr-002 Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tr-002
Search vendor "Qnap" for product "Tr-002"
--
Safe
Qnap
Search vendor "Qnap"
Tr-004u Firmware
Search vendor "Qnap" for product "Tr-004u Firmware"
< 1.0.6
Search vendor "Qnap" for product "Tr-004u Firmware" and version " < 1.0.6"
-
Affected
in Qnap
Search vendor "Qnap"
Tr-004u
Search vendor "Qnap" for product "Tr-004u"
--
Safe