CVE-2021-34349: Command Injection Vulnerability in QVR
Published Sep 27, 2021
·Updated
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Affected Software
1 affected component
QNAP QVR<5.1.5
Remediation
Information
We have already fixed this vulnerability in the following versions of QVR:
QVR 5.1.5 build 20210803 and later
Event History
Sep 27, 2021
CVE Published
via MITRE·12:45 AM
Data Sourced
via MITRE·12:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this command injection vulnerability affecting QNAP devices running QVR?
The vulnerability ID for this command injection vulnerability affecting QNAP devices running QVR is CVE-2021-34349.
2
What is the severity of CVE-2021-34349?
The severity of CVE-2021-34349 is high with a CVSS score of 7.2.
3
How does CVE-2021-34349 affect QNAP devices running QVR?
CVE-2021-34349 allows remote attackers to run arbitrary commands on QNAP devices running QVR.
4
Which versions of QVR have fixed the CVE-2021-34349 vulnerability?
The CVE-2021-34349 vulnerability has been fixed in QVR 5.1.5 build 20210803 and later.
5
Where can I find more information about CVE-2021-34349?
More information about CVE-2021-34349 can be found in the QNAP security advisory QSA-21-35.