{"api_version":"1","generated_at":"2026-07-24T22:14:56+00:00","cve":"CVE-2020-2506","urls":{"html":"https://cve.report/CVE-2020-2506","api":"https://cve.report/api/cve/CVE-2020-2506.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-2506","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-2506"},"summary":{"title":"CVE-2020-2506","description":"The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.","state":"PUBLIC","assigner":"security@qnap.com","published_at":"2021-02-03 16:15:00","updated_at":"2022-10-21 18:56:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-08","name":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-08","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Multiple Vulnerabilities in Helpdesk - Security Advisory | QNAP","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-2506","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2506","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Jose Antonio Pérez Piedra","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"2506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qnap","cpe5":"helpdesk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"2506","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qnap","cpe5":"helpdesk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2020","cve_id":"2506","cve":"CVE-2020-2506","vendorProject":"QNAP Systems","product":"Helpdesk","vulnerabilityName":"QNAP Helpdesk Improper Access Control Vulnerability","dateAdded":"2022-03-25","shortDescription":"QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-04-15","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2020-2506","cwes":"CWE-284","catalogVersion":"2026.07.24","updated_at":"2026-07-24 18:00:38"},"epss":{"cve_year":"2020","cve_id":"2506","cve":"CVE-2020-2506","epss":"0.019820000","percentile":"0.784760000","score_date":"2026-07-23","updated_at":"2026-07-24 00:10:12"},"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@qnap.com","DATE_PUBLIC":"2020-10-07T03:07:00.000Z","ID":"CVE-2020-2506","STATE":"PUBLIC","TITLE":"improper access control vulnerability in Helpdesk"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Helpdesk","version":{"version_data":[{"version_affected":"<","version_value":"3.0.3"}]}}]},"vendor_name":"QNAP Systems Inc."}]}},"credit":[{"lang":"eng","value":"Jose Antonio Pérez Piedra"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284 Improper Access Control"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-08","name":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-08"}]},"solution":[{"lang":"eng","value":"QNAP has already fixed these issues in Helpdesk 3.0.3 and later versions.\n"}],"source":{"advisory":"QSA-20-08","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-02-03 16:15:00","lastModifiedDate":"2022-10-21 18:56:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:qnap:helpdesk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"2506","Ordinal":"162064","Title":"CVE-2020-2506","CVE":"CVE-2020-2506","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"2506","Ordinal":"1","NoteData":"The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"2506","Ordinal":"2","NoteData":"2021-02-03","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"2506","Ordinal":"3","NoteData":"2021-03-11","Type":"Other","Title":"Modified"}]}}}