CVE-2021-38687
Stack Overflow Vulnerability in Surveillance Station
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later
Se ha informado de una vulnerabilidad de desbordamiento del búfer de la pila que afecta al NAS de QNAP que ejecuta Surveillance Station. Si es explotado, esta vulnerabilidad permite a atacantes ejecutar código arbitrario. Ya hemos solucionado esta vulnerabilidad en las siguientes versiones de Surveillance Station: QTS versiones 5.0.0 (64 bits): Surveillance Station versiones 5.2.0.4.2 (26/10/2021) y posteriores QTS versiones 5.0.0 (32 bits): Surveillance Station versiones 5.2.0.3.2 (26/10/2021) y posteriores QTS versiones 4.3.6 (64 bits): Surveillance Station versiones 5.1.5.4.6 (26/10/2021) y posteriores QTS versiones 4.3.6 (32 bits): Surveillance Station versiones 5.1.5.3.6 (26/10/2021) y posteriores QTS versiones 4.3.3: Surveillance Station versiones 5.1.5.3.6 (26/10/2021) y posteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-13 CVE Reserved
- 2021-12-29 CVE Published
- 2024-08-25 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-21-46 | 2022-01-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Surveillance Station Search vendor "Qnap" for product "Surveillance Station" | < 5.2.0.4.2 Search vendor "Qnap" for product "Surveillance Station" and version " < 5.2.0.4.2" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.0.0 Search vendor "Qnap" for product "Qts" and version "5.0.0" | x64 |
Safe
|
Qnap Search vendor "Qnap" | Surveillance Station Search vendor "Qnap" for product "Surveillance Station" | < 5.2.0.3.2 Search vendor "Qnap" for product "Surveillance Station" and version " < 5.2.0.3.2" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 5.0.0 Search vendor "Qnap" for product "Qts" and version "5.0.0" | x86 |
Safe
|
Qnap Search vendor "Qnap" | Surveillance Station Search vendor "Qnap" for product "Surveillance Station" | < 5.1.5.4.6 Search vendor "Qnap" for product "Surveillance Station" and version " < 5.1.5.4.6" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6 Search vendor "Qnap" for product "Qts" and version "4.3.6" | x64 |
Safe
|
Qnap Search vendor "Qnap" | Surveillance Station Search vendor "Qnap" for product "Surveillance Station" | < 5.1.5.3.6 Search vendor "Qnap" for product "Surveillance Station" and version " < 5.1.5.3.6" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6 Search vendor "Qnap" for product "Qts" and version "4.3.6" | x86 |
Safe
|
Qnap Search vendor "Qnap" | Surveillance Station Search vendor "Qnap" for product "Surveillance Station" | < 5.1.5.3.6 Search vendor "Qnap" for product "Surveillance Station" and version " < 5.1.5.3.6" | - |
Affected
| in | Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.3 Search vendor "Qnap" for product "Qts" and version "4.3.3" | - |
Safe
|