CRITICAL

CVE-2020-2506

Qnap Helpdesk 2021-02-03 CVSS v3.1
CVSS
9.8
KEV

Description

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

Summary dbcve.org

This is an improper access control vulnerability in QNAP QTS Helpdesk versions prior to 3.0.3. The flaw allows authenticated or unauthenticated attackers to gain elevated privileges or read sensitive information by bypassing access control checks. The CVSS 9.8 score indicates trivial exploitability with total compromise potential.

Mitigation

Upgrade QNAP QTS Helpdesk to version 3.0.3 or later to remediate this vulnerability. Organizations should also review user access controls and monitor for signs of compromise given the critical severity.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

1.98%
Probability of exploitation in next 30 days
79.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE