CVE-2021-38678: Open Redirect Vulnerability in QcalAgent
Published Jan 14, 2022
·Updated
An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later
Affected Software
1 affected component
QNAP QcalAgent<1.1.7
Remediation
Information
We have already fixed this vulnerability in the following versions of QcalAgent:
QcalAgent 1.1.7 and later
Event History
Jan 14, 2022
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-38678?
CVE-2021-38678 is an open redirect vulnerability that affects QNAP devices running QcalAgent.
2
What is the severity of CVE-2021-38678?
The severity of CVE-2021-38678 is medium, with a CVSS score of 6.1.
3
How does CVE-2021-38678 impact QNAP devices running QcalAgent?
CVE-2021-38678 allows attackers to redirect users to an untrusted page containing malware.
4
Has QNAP already fixed CVE-2021-38678?
Yes, QNAP has fixed CVE-2021-38678 in the QcalAgent version 1.1.7 and above.
5
Where can I find more information about CVE-2021-38678?
You can find more information about CVE-2021-38678 in the QNAP Security Advisory QSA-21-60.