CVE-2020-36197
Summary
| CVE | CVE-2020-36197 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-13 03:15:00 UTC |
| Updated | 2021-06-21 16:56:00 UTC |
| Description | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges, reading sensitive information, executing commands, evading detection, etc. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.3.16 on QTS 4.5.2; versions prior to 5.2.10 on QTS 4.3.6; versions prior to 5.1.14 on QTS 4.3.3; versions prior to 5.3.16 on QuTS hero h4.5.2; versions prior to 5.3.16 on QuTScloud c4.5.4. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Qnap | Music Station | All | All | All | All |
| Operating System | Qnap | Qts | 4.3.3 | - | All | All |
| Operating System | Qnap | Qts | 4.3.6 | - | All | All |
| Operating System | Qnap | Qts | 4.5.2 | - | All | All |
| Operating System | Qnap | Qutscloud | c4.5.4 | All | All | All |
| Application | Qnap | Quts Hero | h4.5.2 | All | All | All |
| Operating System | Qnap | Quts Hero | h4.5.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| QNAP MusicStation / MalwareRemover File Upload / Command Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| ZDI-21-591 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| Improper Access Control Vulnerability in Music Station - Security Advisory | QNAP | MISC | www.qnap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Trend Micro ZDI - ZDI-CAN-12048
There are currently no legacy QID mappings associated with this CVE.