CVE-2020-2504

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
References
Configurations

Configuration 1

cpe:2.3:a:qnap:qes:2.1.1:build_20200211:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200303:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200319:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200424:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:-:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:*:*:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200515:*:*:*:*:*:*
cpe:2.3:a:qnap:qes:2.1.1:build_20200811:*:*:*:*:*:*

Information

Published : 2020-12-24 02:15

Updated : 2020-12-28 03:31


NVD link : CVE-2020-2504

Mitre link : CVE-2020-2504

Products Affected
No products.
CWE