CVE-2021-44055: Information leakage in Video Station
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02/16 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-44055?
CVE-2021-44055 is a missing authorization vulnerability that affects QNAP device running Video Station.
How does CVE-2021-44055 impact QNAP devices?
If exploited, CVE-2021-44055 allows remote attackers to access data or perform actions that they should not be allowed to perform.
Which versions of QNAP Video Station are affected by CVE-2021-44055?
Versions up to 5.1.8, versions between 5.2.0 and 5.3.13, and versions between 5.4.0 and 5.5.9 of QNAP Video Station are affected by CVE-2021-44055.
What is the severity of CVE-2021-44055?
CVE-2021-44055 has a severity rating of 9.8, indicating it is critical.
How can I fix CVE-2021-44055?
To fix CVE-2021-44055, update your QNAP Video Station to a version that is not affected by the vulnerability.