CVE-2021-34345
Summary
| CVE | CVE-2021-34345 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-10 04:15:00 UTC |
| Updated | 2022-02-10 07:44:00 UTC |
| Description | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qnap | Ej1600 | - | All | All | All |
| Operating System | Qnap | Ej1600 Firmware | All | All | All | All |
| Hardware | Qnap | Tl-d1600s | - | All | All | All |
| Operating System | Qnap | Tl-d1600s Firmware | All | All | All | All |
| Hardware | Qnap | Tl-d400s | - | All | All | All |
| Operating System | Qnap | Tl-d400s Firmware | All | All | All | All |
| Hardware | Qnap | Tl-d800c | - | All | All | All |
| Operating System | Qnap | Tl-d800c Firmware | All | All | All | All |
| Hardware | Qnap | Tl-d800s | - | All | All | All |
| Operating System | Qnap | Tl-d800s Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r1200c-rp | - | All | All | All |
| Operating System | Qnap | Tl-r1200c-rp Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r1200s-rp | - | All | All | All |
| Operating System | Qnap | Tl-r1200s-rp Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r1220sep-rp | - | All | All | All |
| Operating System | Qnap | Tl-r1220sep-rp Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r1620sdc | - | All | All | All |
| Operating System | Qnap | Tl-r1620sdc Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r1620sep-rp | - | All | All | All |
| Operating System | Qnap | Tl-r1620sep-rp Firmware | All | All | All | All |
| Hardware | Qnap | Tl-r400s | - | All | All | All |
| Operating System | Qnap | Tl-r400s Firmware | All | All | All | All |
| Hardware | Qnap | Tr-002 | - | All | All | All |
| Operating System | Qnap | Tr-002 Firmware | All | All | All | All |
| Hardware | Qnap | Tr-004 | - | All | All | All |
| Hardware | Qnap | Tr-004u | - | All | All | All |
| Operating System | Qnap | Tr-004u Firmware | All | All | All | All |
| Operating System | Qnap | Tr-004 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stack-Based Buffer Overflow Vulnerabilities in NVR Storage Expansion - Security Advisory | QNAP | CONFIRM | www.qnap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: crixer
There are currently no legacy QID mappings associated with this CVE.