U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-38682

Change History

CVE Modified by QNAP Systems, Inc. 1/13/2022 10:15:44 PM

Action Type Old Value New Value
Changed Description
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code.
We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard:
QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later
QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later
QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later
QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later
QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later
QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later
QTS 4.5.4: QVR Guard 2.1.3.0 and later
QTS 5.0.0: QVR Guard 2.1.3.0 and later
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 and later QTS 5.0.0: QVR Guard 2.1.3.0 and later