CVE-2020-2506
Description
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
Summary dbcve.org
This is an improper access control vulnerability in QNAP QTS Helpdesk versions prior to 3.0.3. The flaw allows authenticated or unauthenticated attackers to gain elevated privileges or read sensitive information by bypassing access control checks. The CVSS 9.8 score indicates trivial exploitability with total compromise potential.
Mitigation
Upgrade QNAP QTS Helpdesk to version 3.0.3 or later to remediate this vulnerability. Organizations should also review user access controls and monitor for signs of compromise given the critical severity.