First published: Mon Nov 16 2020(Updated: )
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <4.4.3.1421 |
QNAP has already fixed these issues in QTS 4.4.3.1421 build 20200907 and later versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2492 is considered a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2020-2492, upgrade your QTS version to 4.4.3.1421 or later.
CVE-2020-2492 affects QNAP Systems Inc. QTS versions prior to 4.4.3.1421.
CVE-2020-2492 is a command injection vulnerability that can be exploited by remote attackers.
Yes, if successfully exploited, CVE-2020-2492 can allow attackers to execute arbitrary commands, potentially leading to data compromise.