First published: Wed Dec 29 2021(Updated: )
A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Surveillance Station | <5.2.0.4.2 | |
QNAP QTS | =5.0.0 | |
Qnap Surveillance Station | <5.2.0.3.2 | |
QNAP QTS | =5.0.0 | |
Qnap Surveillance Station | <5.1.5.4.6 | |
QNAP QTS | =4.3.6 | |
Qnap Surveillance Station | <5.1.5.3.6 | |
QNAP QTS | =4.3.6 | |
QNAP QTS | =4.3.3 |
We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38687 is a stack buffer overflow vulnerability that affects QNAP NAS running Surveillance Station.
The severity of CVE-2021-38687 is critical with a CVSS 3.1 score of 9.8.
QNAP Surveillance Station versions up to but excluding 5.2.0.4.2 are affected by CVE-2021-38687.
You can fix CVE-2021-38687 by updating Surveillance Station to version 5.2.0.4.2 or later.
You can find more information about CVE-2021-38687 in the QNAP security advisory QSA-21-46.