← Back

CVE-2020-2509

nvd nist
Published: Apr 17, 2021Modified: Oct 27, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

Affected (86)

Products: Qnap: Qts, Quts Hero
2 products
Qts
Quts Hero
Configuration A
86 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Before 4.2.6
From 4.3.5 to 4.3.6
From 4.4.0 to 4.5.1
Version 4.2.6
Version 4.2.6 build_20170517
Version 4.2.6 build_20190322
Version 4.2.6 build_20190730
Version 4.2.6 build_20190921
Version 4.2.6 build_20191107
Version 4.2.6 build_20200109
Version 4.2.6 build_20200421
Version 4.2.6 build_20200611
Version 4.2.6 build_20200821
Version 4.3.3.0174
Version 4.3.3.0868
Version 4.3.3.0998
Version 4.3.3.1051
Version 4.3.3.1098
Version 4.3.3.1161
Version 4.3.3.1252
Version 4.3.3.1315
Version 4.3.3.1386
Version 4.3.3.1432
Version 4.3.4.0358
Version 4.3.4.0358 beta1
Version 4.3.4.0370
Version 4.3.4.0370 beta1
Version 4.3.4.0372
Version 4.3.4.0372 beta1
Version 4.3.4.0374
Version 4.3.4.0374 beta1
Version 4.3.4.0387
Version 4.3.4.0387 beta2
Version 4.3.4.0411
Version 4.3.4.0416
Version 4.3.4.0427
Version 4.3.4.0434
Version 4.3.4.0435
Version 4.3.4.0451
Version 4.3.4.0483
Version 4.3.4.0486
Version 4.3.4.0506
Version 4.3.4.0516
Version 4.3.4.0526
Version 4.3.4.0551
Version 4.3.4.0557
Version 4.3.4.0561
Version 4.3.4.0569
Version 4.3.4.0593
Version 4.3.4.0597
Version 4.3.4.0604
Version 4.3.4.0899
Version 4.3.4.1029
Version 4.3.4.1082
Version 4.3.4.1190
Version 4.3.4.1282
Version 4.3.4.1368
Version 4.3.4.1417
Version 4.3.4.1463
Version 4.3.6.0895
Version 4.3.6.0907
Version 4.3.6.0923
Version 4.3.6.0944
Version 4.3.6.0959
Version 4.3.6.0979
Version 4.3.6.0993
Version 4.3.6.1013
Version 4.3.6.1033
Version 4.3.6.1070
Version 4.3.6.1154
Version 4.3.6.1218
Version 4.3.6.1263
Version 4.3.6.1286
Version 4.3.6.1333
Version 4.3.6.1411
Version 4.3.6.1446
Version 4.3.6
Version 4.5.1.1456
Version 4.5.1.1461
Version 4.5.1.1465
Version 4.5.1.1480
Version 4.5.1
Version 4.5.2
Qnap
Before h4.5.1
Version h4.5.1.1472
Version h4.5.1

References (3)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.