Security ID : QSA-21-37

Insufficiently Protected Credentials in QSW-M2116P-2T2S and QuNetSwitch


  • Release date : September 10, 2021

  • CVE identifier : CVE-2021-28813

  • Affected products: QSW-M2116P-2T2S, QNAP switches running QuNetSwitch

Severity

Important

Status

Resolved


Summary

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.

We have already fixed this vulnerability in the following versions:

  • QSW-M2116P-2T2S 1.0.6 build 210713 and later
  • QGD-1600P: QuNetSwitch 1.0.6.1509 and later
  • QGD-1602P: QuNetSwitch 1.0.6.1509 and later
  • QGD-3014PT: QuNetSwitch 1.0.6.1519 and later

Recommendation

To secure your device, we recommend regularly updating your system and applications to the latest versions to benefit from vulnerability fixes.

Updating QSW-M2116P-2T2S

  1. Log on to QSS.
  2. Go to System > Firmware Update > Live Update.
  3. Click Check for Update.
    QSS checks for available firmware updates.
  4. Click Update System.
    A confirmation message appears.
  5. Click Update.
  6. QSS downloads and installs the latest available update.

Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating QuNetSwitch

  1. Log on to QTS as administrator.
  2. Open the App Center and then click .
    A search box appears.
  3. Type “QuNetSwitch” and then press ENTER.
    QuNetSwitch appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your QuNetSwitch is already up to date.
  5. Click OK.
    The application is updated.

Revision History: V1.0 (September 10, 2021) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      back to top