Skip to content
COOEY

EXPOSURES › CVE-2020-2509

CVE-2020-2509

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-2509 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

QNAP NAS devices suffered a command injection vulnerability enabling remote code execution, actively exploited in ransomware campaigns.

QNAP NAS devices contained a command injection flaw allowing attackers to execute arbitrary code remotely. This vulnerability was actively exploited in the wild, leading to data breaches and system compromises, particularly in ransomware attacks. DIB organizations must ensure their storage infrastructure is patched and monitored for signs of exploitation, as QNAP has a history of critical, unpatched vulnerabilities.

Shame score — The vulnerability was actively exploited in ransomware campaigns, indicating a severe failure in patch management and security posture that directly led to data breaches and system compromises.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.