{"api_version":"1","generated_at":"2026-07-24T03:46:00+00:00","cve":"CVE-2021-38688","urls":{"html":"https://cve.report/CVE-2021-38688","api":"https://cve.report/api/cve/CVE-2021-38688.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-38688","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-38688"},"summary":{"title":"CVE-2021-38688","description":"An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later","state":"PUBLIC","assigner":"security@qnap.com","published_at":"2021-12-29 13:15:00","updated_at":"2022-01-10 20:01:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-21-55","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Improper Authentication Vulnerability in Qfile - Security Advisory | QNAP","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-38688","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38688","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Code Ninja","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"38688","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qnap","cpe5":"qfile","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@qnap.com","DATE_PUBLIC":"2021-12-09T22:29:00.000Z","ID":"CVE-2021-38688","STATE":"PUBLIC","TITLE":"Improper Authentication in Qfile"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Qfile","version":{"version_data":[{"version_affected":"<","version_value":"3.0.0.1105"}]}}]},"vendor_name":"QNAP Systems Inc."}]}},"credit":[{"lang":"eng","value":"Code Ninja"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later"}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287 Improper Authentication"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.qnap.com/en/security-advisory/qsa-21-55","name":"https://www.qnap.com/en/security-advisory/qsa-21-55"}]},"solution":[{"lang":"eng","value":"We have already fixed this vulnerability in the following versions of Qfile:\nQfile 3.0.0.1105 and later\n"}],"source":{"advisory":"QSA-21-55","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-12-29 13:15:00","lastModifiedDate":"2022-01-10 20:01:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:qnap:qfile:*:*:*:*:*:android:*:*","versionEndExcluding":"3.0.0.1105","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"38688","Ordinal":"214359","Title":"CVE-2021-38688","CVE":"CVE-2021-38688","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"38688","Ordinal":"1","NoteData":"An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later","Type":"Description","Title":null},{"CveYear":"2021","CveId":"38688","Ordinal":"2","NoteData":"2021-12-29","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"38688","Ordinal":"3","NoteData":"2021-12-29","Type":"Other","Title":"Modified"}]}}}