← Back

CVE-2020-2504

nvd nist
Published: Dec 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Affected (8)

Products: Qnap: Qes
1 product
Qes
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Before 2.1.1
Version 2.1.1
Version 2.1.1 build_20200211
Version 2.1.1 build_20200303
Version 2.1.1 build_20200319
Version 2.1.1 build_20200424
Version 2.1.1 build_20200515
Version 2.1.1 build_20200811

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.