CVE-2021-38685: Command Injection Vulnerability in VioStor
Published Nov 26, 2021
·Updated
A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR FW 5.1.6 build 20211109 and later
Affected Software
1 affected component
QNAP QVR<5.1.6
Remediation
Information
We have already fixed this vulnerability in the following versions of QVR:
QVR FW 5.1.6 build 20211109 and later
Event History
Nov 26, 2021
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-38685?
CVE-2021-38685 is a command injection vulnerability that affects QNAP device, VioStor.
2
What is the severity of CVE-2021-38685?
CVE-2021-38685 has a severity rating of 9.8 (Critical).
3
How does CVE-2021-38685 affect QNAP device, VioStor?
CVE-2021-38685 allows remote attackers to run arbitrary commands on the affected QNAP device, VioStor.
4
Has QNAP fixed CVE-2021-38685?
Yes, QNAP has fixed CVE-2021-38685 in the following versions of QVR: QVR FW 5.1.6 build 20211109 and later.
5
Where can I find more information about CVE-2021-38685?
You can find more information about CVE-2021-38685 in the QNAP security advisory QSA-21-51.