CVE-2021-38682: Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 and later QTS 5.0.0: QVR Guard 2.1.3.0 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this stack buffer overflow vulnerability?
The vulnerability ID for this stack buffer overflow vulnerability is CVE-2021-38682.
Which QNAP devices are affected by this vulnerability?
This vulnerability affects QNAP devices running QVR Elite, QVR Pro, and QVR Guard.
What is the severity rating for CVE-2021-38682?
The severity rating for CVE-2021-38682 is critical with a score of 9.8.
How can this vulnerability be exploited?
If exploited, this vulnerability allows attackers to execute arbitrary code.
Has this vulnerability been fixed?
Yes, this vulnerability has already been fixed in the following versions of QVR Elite, QVR Pro, and QVR Guard: QuTS ...