CVE-2020-2504

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qnap:qes:*:*:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:-:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200211:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200303:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200319:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200424:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200515:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200811:*:*:*:*:*:*

History

21 Nov 2024, 05:25

Type Values Removed Values Added
References () https://www.qnap.com/zh-tw/security-advisory/qsa-20-17 - Vendor Advisory () https://www.qnap.com/zh-tw/security-advisory/qsa-20-17 - Vendor Advisory
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 5.8

Information

Published : 2020-12-24 02:15

Updated : 2024-11-21 05:25


NVD link : CVE-2020-2504

Mitre link : CVE-2020-2504

CVE.ORG link : CVE-2020-2504


JSON object : View

Products Affected

qnap

  • qes
CWE
CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path

CWE-284

Improper Access Control