First published: Thu May 13 2021(Updated: )
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Malware Remover | >=4.5.4.0<4.6.1.0 | |
QNAP NAS |
QNAP have already fixed the issue in the following versions: QTS 4.4.x: Malware Remover 4.6.1.0 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36198 is a vulnerability that allows local attackers to escalate privileges on affected installations of QNAP NAS.
CVE-2020-36198 affects QNAP NAS by allowing local attackers to escalate privileges.
Yes, authentication is required to exploit CVE-2020-36198.
The Malware Remover application is affected by CVE-2020-36198.
To fix CVE-2020-36198, update your QNAP NAS to version 4.6.1.0 or later.