Skip to content
COOEY

EXPOSURES › CVE-2020-2506

CVE-2020-2506

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-2506 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

QNAP Helpdesk suffered an improper access control flaw allowing privilege escalation or data exposure.

The QNAP Helpdesk product contained an improper access control vulnerability that could allow attackers to gain privileges or read sensitive information. This failure impacts DIB organizations by exposing sensitive data and enabling privilege escalation, requiring immediate patching and access control reviews. The flaw was actively exploited in the wild, indicating a significant compliance and security risk.

Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch known issues and a significant security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.