CVE-2021-38687: Stack Overflow Vulnerability in Surveillance Station
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-38687?
CVE-2021-38687 is a stack buffer overflow vulnerability that affects QNAP NAS running Surveillance Station.
What is the severity of CVE-2021-38687?
The severity of CVE-2021-38687 is critical with a CVSS 3.1 score of 9.8.
Which software versions are affected by CVE-2021-38687?
QNAP Surveillance Station versions up to but excluding 5.2.0.4.2 are affected by CVE-2021-38687.
How can I fix CVE-2021-38687?
You can fix CVE-2021-38687 by updating Surveillance Station to version 5.2.0.4.2 or later.
Where can I find more information about CVE-2021-38687?
You can find more information about CVE-2021-38687 in the QNAP security advisory QSA-21-46.