CVE-2021-28814

HIGH

QNAP Helpdesk < 3.0.4 - Improper Privilege Management

Title source: llm
STIX 2.1

Description

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0060
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
qnap/helpdesk < 3.0.4
Published Jun 11, 2021
Tracked Since Feb 18, 2026