An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Iptime
Subscribe
|
Nas-i
Subscribe
Nas-i Firmware
Subscribe
Nas-ii
Subscribe
Nas-ii Firmware
Subscribe
Nas-iie
Subscribe
Nas-iie Firmware
Subscribe
Nas101
Subscribe
Nas101 Firmware
Subscribe
Nas1dual
Subscribe
Nas1dual Firmware
Subscribe
Nas2dual
Subscribe
Nas2dual Firmware
Subscribe
Nas3
Subscribe
Nas3 Firmware
Subscribe
Nas4
Subscribe
Nas4 Firmware
Subscribe
Nas4dual
Subscribe
Nas4dual Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-13414 | An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: krcert
Published:
Updated: 2024-08-03T20:26:25.555Z
Reserved: 2021-02-03T00:00:00
Link: CVE-2021-26620
No data.
Status : Modified
Published: 2022-03-25T19:15:08.687
Modified: 2024-11-21T05:56:36.370
Link: CVE-2021-26620
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD