CVE-2021-34346
Summary
| CVE | CVE-2021-34346 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-10 04:15:00 UTC |
| Updated | 2022-02-10 07:45:00 UTC |
| Description | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qnap | Nvr Storage Expansion | - | All | All | All |
| Operating System | Qnap | Nvr Storage Expansion Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stack-Based Buffer Overflow Vulnerabilities in NVR Storage Expansion - Security Advisory | QNAP | CONFIRM | www.qnap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: crixer
There are currently no legacy QID mappings associated with this CVE.