CVE-2021-34360
CSRF Bypass in Proxy Server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Se ha informado de una vulnerabilidad de tipo cross-site request forgery (CSRF) que afecta al dispositivo QNAP ejecutando Servidor Proxy. Si es explotado, esta vulnerabilidad permite a atacantes remotos inyectar código malicioso. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) y posteriores QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) y posteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-08 CVE Reserved
- 2022-05-26 CVE Published
- 2024-08-17 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-22-18 | 2022-06-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Nas Proxy Server Search vendor "Qnap" for product "Nas Proxy Server" | >= 1.4.0 < 1.4.2 Search vendor "Qnap" for product "Nas Proxy Server" and version " >= 1.4.0 < 1.4.2" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.5.1 <= 4.5.4.2012 Search vendor "Qnap" for product "Qts" and version " >= 4.5.1 <= 4.5.4.2012" | - |
Safe
|
Qnap Search vendor "Qnap" | Nas Proxy Server Search vendor "Qnap" for product "Nas Proxy Server" | >= 1.4.0 < 1.4.3 Search vendor "Qnap" for product "Nas Proxy Server" and version " >= 1.4.0 < 1.4.3" | - |
Affected
| in | Qnap Search vendor "Qnap" | Quts Hero Search vendor "Qnap" for product "Quts Hero" | h5.0.0 Search vendor "Qnap" for product "Quts Hero" and version "h5.0.0" | - |
Safe
|
Qnap Search vendor "Qnap" | Nas Proxy Server Search vendor "Qnap" for product "Nas Proxy Server" | >= 1.4.0 < 1.4.2 Search vendor "Qnap" for product "Nas Proxy Server" and version " >= 1.4.0 < 1.4.2" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qutscloud Search vendor "Qnap" for product "Qutscloud" | c4.5.6 Search vendor "Qnap" for product "Qutscloud" and version "c4.5.6" | - |
Safe
|