Vulnerability Details CVE-2020-2506
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.292
EPSS Ranking 96.3%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 7.5
Proposed Action
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Ransomware Campaign
Unknown
Products affected by CVE-2020-2506
-
cpe:2.3:a:qnap:helpdesk:-
-
cpe:2.3:a:qnap:helpdesk:1.0.06
-
cpe:2.3:a:qnap:helpdesk:1.0.10
-
cpe:2.3:a:qnap:helpdesk:1.0.12
-
cpe:2.3:a:qnap:helpdesk:1.0.14
-
cpe:2.3:a:qnap:helpdesk:1.1.01
-
cpe:2.3:a:qnap:helpdesk:1.1.02
-
cpe:2.3:a:qnap:helpdesk:1.1.04
-
cpe:2.3:a:qnap:helpdesk:1.1.10
-
cpe:2.3:a:qnap:helpdesk:1.1.12
-
cpe:2.3:a:qnap:helpdesk:1.1.15
-
cpe:2.3:a:qnap:helpdesk:1.1.16
-
cpe:2.3:a:qnap:helpdesk:1.1.17
-
cpe:2.3:a:qnap:helpdesk:1.1.18
-
cpe:2.3:a:qnap:helpdesk:1.1.19
-
cpe:2.3:a:qnap:helpdesk:1.1.20
-
cpe:2.3:a:qnap:helpdesk:1.1.21
-
cpe:2.3:a:qnap:helpdesk:1.2
-
cpe:2.3:a:qnap:helpdesk:1.2.1
-
cpe:2.3:a:qnap:helpdesk:1.2.2
-
cpe:2.3:a:qnap:helpdesk:1.2.3
-
cpe:2.3:a:qnap:helpdesk:1.2.4
-
cpe:2.3:a:qnap:helpdesk:2.0.0
-
cpe:2.3:a:qnap:helpdesk:2.0.1
-
cpe:2.3:a:qnap:helpdesk:2.1.0
-
cpe:2.3:a:qnap:helpdesk:3.0.0
-
cpe:2.3:a:qnap:helpdesk:3.0.1