First published: Thu Dec 24 2020(Updated: )
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap QES | <2.1.1 | |
Qnap QES | =2.1.1 | |
Qnap QES | =2.1.1-build_20200211 | |
Qnap QES | =2.1.1-build_20200303 | |
Qnap QES | =2.1.1-build_20200319 | |
Qnap QES | =2.1.1-build_20200424 | |
Qnap QES | =2.1.1-build_20200515 | |
Qnap QES | =2.1.1-build_20200811 |
QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2504 is considered a high severity vulnerability due to its ability to allow absolute path traversal.
To fix CVE-2020-2504, upgrade to QES 2.1.1 Build 20201006 or later.
CVE-2020-2504 affects QNAP QES versions earlier than 2.1.1.
Yes, CVE-2020-2504 can be exploited remotely by an attacker through File Station.
Exploitation of CVE-2020-2504 can lead to unauthorized access to sensitive files on the system.