CVE-2021-44055 MEDIUM

CVE-2021-44055: Information leakage in Video Station

Vendor Qnap Systems Inc.
Product Video Station
Weakness CWE-862 · Missing authorization
Published May 5, 2022
Last update September 17, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02/16 ) and later

Key dates

02Disclosure timeline

May 5, 2022 CVE published
September 17, 2024 Record updated