CVE-2021-28810

HIGH

Roon Server < 2021-05-18 - Authentication Bypass

Title source: llm
STIX 2.1

Description

If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-290
Status published
Products (1)
qnap/roon_server < 2021-05-18
Published Jun 08, 2021
Tracked Since Feb 18, 2026