Lucene search

K
cvelistQnapCVELIST:CVE-2020-2506
HistoryOct 07, 2020 - 12:00 a.m.

CVE-2020-2506 improper access control vulnerability in Helpdesk

2020-10-0700:00:00
CWE-284
qnap
www.cve.org
2

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

9.6 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.8%

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CNA Affected

[
  {
    "product": "Helpdesk",
    "vendor": "QNAP Systems Inc.",
    "versions": [
      {
        "lessThan": "3.0.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

9.6 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.8%