Junglewise Threat Intelligence

CVE-2020-2506: QNAP Helpdesk Improper Access Control Vulnerability

CVE-2020-2506 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: QNAP Systems Helpdesk. Vendors: QNAP Systems, Inc., QNAP Systems.

Executive brief

QNAP Helpdesk contains an improper access control vulnerability in versions prior to 3.0.3. If exploited, this flaw allows remote attackers to gain elevated privileges or read sensitive information, potentially compromising the security of the software.

Affected products

  • QNAP Systems Inc. Helpdesk prior to 3.0.3

Timeline

  • 2021-02-03: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Reported as exploited in the wild in CISA KEV catalog