← Back

CVE-2020-36195

nvd nist
Published: Apr 17, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later

Affected (56)

3 products
Qts
Media Streaming Add On
Multimedia Console
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Before 4.3.3
From 4.3.4 to 4.3.6
Version 4.3.3.0095
Version 4.3.3.0096
Version 4.3.3.0136
Version 4.3.3.0154
Version 4.3.3.0174
Version 4.3.3.0188
Version 4.3.3.0210
Version 4.3.3.0229
Version 4.3.3.0238
Version 4.3.3.0262
Version 4.3.3.0299
Version 4.3.3.0351
Version 4.3.3.0353
Version 4.3.3.0361
Version 4.3.3.0369
Version 4.3.3.0378
Version 4.3.3.0396
Version 4.3.3.0404
Version 4.3.3.0416
Version 4.3.3.0418
Version 4.3.3.0448
Version 4.3.3.0514
Version 4.3.3.0546
Version 4.3.3.0570
Version 4.3.3.0868
Version 4.3.3.0998
Version 4.3.3.1051
Version 4.3.3.1098
Version 4.3.3.1161
Version 4.3.3.1252
Version 4.3.3.1315
Version 4.3.3.1386
Version 4.3.3.1432
Version 4.3.6.0895
Version 4.3.6.0907
Version 4.3.6.0923
Version 4.3.6.0944
Version 4.3.6.0959
Version 4.3.6.0979
Version 4.3.6.0993
Version 4.3.6.1013
Version 4.3.6.1033
Version 4.3.6.1070
Version 4.3.6.1154
Version 4.3.6.1218
Version 4.3.6.1263
Version 4.3.6.1286
Version 4.3.6.1333
Version 4.3.6.1411
Version 4.3.6.1446
Version 4.3.6
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 430.1.8.10
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.3
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 430.1.8.8
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.6
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.4
Running on/withPlatform Versions
Qnap
Qts
From 4.4.0

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.