We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-44052

Arbitrary file read



Assignerqnap
Reserved2021-11-19
Published2022-05-05
Updated2024-09-16

Description

An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, and QTS: QuTScloud c5.0.1.1998 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 4.3.4.1976 build 20220303 and later QTS 4.3.3.1945 build 20220303 and later QTS 4.2.6 build 20220304 and later QTS 4.3.6.1965 build 20220302 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later



MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Product status

Any version before c5.0.1.1998
affected

Any version before h4.5.4.1971 build 20220310
affected

Any version before h5.0.0.1986 build 20220324
affected

Any version before 4.3.4.1976 build 20220303
affected

Any version before 4.3.3.1945 build 20220303
affected

Any version before 4.2.6 build 20220304
affected

Any version before 4.3.6.1965 build 20220302
affected

Any version before 5.0.0.1986 build 20220324
affected

Any version before 4.5.4.1991 build 20220329
affected

Credits

Enio Pena Navarro and Michael Messner from Siemens Energy AG

References

https://www.qnap.com/en/security-advisory/qsa-22-16

cve.org CVE-2021-44052

nvd.nist.gov CVE-2021-44052

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2021-44052
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.