CVE-2020-2506
published 2021-02-03CVE-2020-2506: The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
1.98%
78.4th percentile
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | helpdesk | < 3.0.3 | 3.0.3 |
| qnap_systems_inc | helpdesk | >= unspecified < 3.0.3 | 3.0.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability affects QNAP Helpdesk versions prior to 3.0.3; detect outdated Helpdesk installations by identifying version strings below 3.0.3 in network traffic or host-based inventory ↗
- →Monitor for privilege escalation or unauthorized access to sensitive information on QNAP QTS systems running vulnerable Helpdesk versions, as exploitation enables privilege gain or sensitive data read ↗
- ·Vulnerability is confirmed exploited in the wild per CISA KEV; remediation deadline was 2022-04-15, meaning unpatched internet-facing QNAP devices remain high-priority targets ↗
- ·The vulnerability also affects earlier versions of QTS (the QNAP operating system), not just the Helpdesk application in isolation ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.3HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vph4-5mf4-28v5: The vulnerability have been reported to affect earlier versions of QTS
ghsa_unreviewed·2022-05-24
CVE-2020-2506 [CRITICAL] CWE-284 GHSA-vph4-5mf4-28v5: The vulnerability have been reported to affect earlier versions of QTS
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to obtain control of a QNAP device. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
VulnCheck
QNAP Helpdesk Improper Access Control Vulnerability
vulncheck·2020·CVSS 7.3
CVE-2020-2506 [HIGH] CWE-284 QNAP Helpdesk Improper Access Control Vulnerability
QNAP Helpdesk Improper Access Control Vulnerability
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Affected: QNAP Helpdesk
Required Action: Apply updates per vendor instructions.
Exploitation References: https://blog.netlab.360.com/qnap-nas-users-make-sure-you-check-your-system/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
CISA
QNAP Helpdesk Improper Access Control Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2020-2506 [CRITICAL] CWE-284 QNAP Helpdesk Improper Access Control Vulnerability
Vulnerability: QNAP Helpdesk Improper Access Control Vulnerability
Affected: QNAP Systems Helpdesk
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-2506
Remediation Due Date: 2022-04-15
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-03
Published
2022-03-25
Added to CISA KEV
Exploited in the wild