CVE-2020-2504: Absolute path traversal vulnerability in QES
Published Dec 24, 2020
·Updated
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Affected Software
8 affected components
QNAP QES<2.1.1
QNAP QES=2.1.1
QNAP QES=2.1.1-build_20200211
QNAP QES=2.1.1-build_20200303
QNAP QES=2.1.1-build_20200319
QNAP QES=2.1.1-build_20200424
QNAP QES=2.1.1-build_20200515
QNAP QES=2.1.1-build_20200811
Remediation
Information
QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Event History
Dec 24, 2020
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-2504?
CVE-2020-2504 is considered a high severity vulnerability due to its ability to allow absolute path traversal.
2
How do I fix CVE-2020-2504?
To fix CVE-2020-2504, upgrade to QES 2.1.1 Build 20201006 or later.
3
What systems are affected by CVE-2020-2504?
CVE-2020-2504 affects QNAP QES versions earlier than 2.1.1.
4
Can CVE-2020-2504 be exploited remotely?
Yes, CVE-2020-2504 can be exploited remotely by an attacker through File Station.
5
What is the impact of exploiting CVE-2020-2504?
Exploitation of CVE-2020-2504 can lead to unauthorized access to sensitive files on the system.