CVE-2020-2506
Summary
| CVE | CVE-2020-2506 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-03 16:15:00 UTC |
| Updated | 2022-10-21 18:56:00 UTC |
| Description | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. |
Risk And Classification
EPSS: 0.019820000 probability, percentile 0.784620000 (date 2026-07-22)
CISA KEV: Listed on 2022-03-25; due 2022-04-15; ransomware use Unknown
Problem Types: NVD-CWE-Other
CISA Known Exploited Vulnerability
| Vendor | QNAP Systems |
|---|---|
| Product | Helpdesk |
| Name | QNAP Helpdesk Improper Access Control Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-2506 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities in Helpdesk - Security Advisory | QNAP | CONFIRM | www.qnap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: Jose Antonio Pérez Piedra
There are currently no legacy QID mappings associated with this CVE.