← Back

CVE-2020-36197

nvd nist
Published: May 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges, reading sensitive information, executing commands, evading detection, etc. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.3.16 on QTS 4.5.2; versions prior to 5.2.10 on QTS 4.3.6; versions prior to 5.1.14 on QTS 4.3.3; versions prior to 5.3.16 on QuTS hero h4.5.2; versions prior to 5.3.16 on QuTScloud c4.5.4.

Affected (3)

Products: Qnap: Music Station
1 product
Music Station
Configuration A
1 platform
Running on/withPlatform Versions
Qnap
Qts
Version 4.5.2
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.2.10
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.6
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.1.14
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.3
Configuration D
1 platform
Running on/withPlatform Versions
Qnap
Quts Hero
Version h4.5.2
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.3.16
Running on/withPlatform Versions
Qnap
Qutscloud
Version c4.5.4

References (6)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: security@qnapsecurity.com.tw
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.