HIGH · 7.5

CVE-2021-26620

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerab...

Vulnerability Description

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IptimeNas101 Firmware< 1.4.82
IptimeNas101-
IptimeNas1Dual Firmware< 1.4.82
IptimeNas1Dual-
IptimeNas2Dual Firmware< 1.4.82
IptimeNas2Dual-
IptimeNas3 Firmware< 1.4.82
IptimeNas3-
IptimeNas4 Firmware< 1.4.82
IptimeNas4-
IptimeNas4Dual Firmware< 1.4.82
IptimeNas4Dual-
IptimeNas-I Firmware< 1.4.82
IptimeNas-I-
IptimeNas-Ii Firmware< 1.4.82
IptimeNas-Ii-
IptimeNas-Iie Firmware< 1.4.82
IptimeNas-Iie-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-26620?

CVE-2021-26620 is a vulnerability with a CVSS score of 7.5 (HIGH). An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerab...

How severe is CVE-2021-26620?

CVE-2021-26620 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-26620?

Check the references section above for vendor advisories and patch information. Affected products include: Iptime Nas101 Firmware, Iptime Nas101, Iptime Nas1Dual Firmware, Iptime Nas1Dual, Iptime Nas2Dual Firmware.