cbcvebase.
CVE-2020-2506
published 2021-02-03

CVE-2020-2506: The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to…

PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
1.98%
78.4th percentile
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

Affected

2 ranges
VendorProductVersion rangeFixed in
qnaphelpdesk< 3.0.33.0.3
qnap_systems_inchelpdesk>= unspecified < 3.0.33.0.3

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability affects QNAP Helpdesk versions prior to 3.0.3; detect outdated Helpdesk installations by identifying version strings below 3.0.3 in network traffic or host-based inventory
  • Monitor for privilege escalation or unauthorized access to sensitive information on QNAP QTS systems running vulnerable Helpdesk versions, as exploitation enables privilege gain or sensitive data read
  • ·Vulnerability is confirmed exploited in the wild per CISA KEV; remediation deadline was 2022-04-15, meaning unpatched internet-facing QNAP devices remain high-priority targets
  • ·The vulnerability also affects earlier versions of QTS (the QNAP operating system), not just the Helpdesk application in isolation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.3HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.