CVE-2020-2509

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
qnapCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
qnapqts
𝑥
< 4.2.6
qnapqts
4.3.5 ≤
𝑥
< 4.3.6
qnapqts
4.4.0 ≤
𝑥
< 4.5.1
qnapqts
4.2.6
qnapqts
4.2.6:build_20170517
qnapqts
4.2.6:build_20190322
qnapqts
4.2.6:build_20190730
qnapqts
4.2.6:build_20190921
qnapqts
4.2.6:build_20191107
qnapqts
4.2.6:build_20200109
qnapqts
4.2.6:build_20200421
qnapqts
4.2.6:build_20200611
qnapqts
4.2.6:build_20200821
qnapqts
4.3.3.0174
qnapqts
4.3.3.0868
qnapqts
4.3.3.0998
qnapqts
4.3.3.1051
qnapqts
4.3.3.1098
qnapqts
4.3.3.1161
qnapqts
4.3.3.1252
qnapqts
4.3.3.1315
qnapqts
4.3.3.1386
qnapqts
4.3.3.1432
qnapqts
4.3.4.0358
qnapqts
4.3.4.0358:beta1
qnapqts
4.3.4.0370
qnapqts
4.3.4.0370:beta1
qnapqts
4.3.4.0372
qnapqts
4.3.4.0372:beta1
qnapqts
4.3.4.0374
qnapqts
4.3.4.0374:beta1
qnapqts
4.3.4.0387
qnapqts
4.3.4.0387:beta2
qnapqts
4.3.4.0411
qnapqts
4.3.4.0416
qnapqts
4.3.4.0427
qnapqts
4.3.4.0434
qnapqts
4.3.4.0435
qnapqts
4.3.4.0451
qnapqts
4.3.4.0483
qnapqts
4.3.4.0486
qnapqts
4.3.4.0506
qnapqts
4.3.4.0516
qnapqts
4.3.4.0526
qnapqts
4.3.4.0551
qnapqts
4.3.4.0557
qnapqts
4.3.4.0561
qnapqts
4.3.4.0569
qnapqts
4.3.4.0593
qnapqts
4.3.4.0597
qnapqts
4.3.4.0604
qnapqts
4.3.4.0899
qnapqts
4.3.4.1029
qnapqts
4.3.4.1082
qnapqts
4.3.4.1190
qnapqts
4.3.4.1282
qnapqts
4.3.4.1368
qnapqts
4.3.4.1417
qnapqts
4.3.4.1463
qnapqts
4.3.6
qnapqts
4.3.6.0895
qnapqts
4.3.6.0907
qnapqts
4.3.6.0923
qnapqts
4.3.6.0944
qnapqts
4.3.6.0959
qnapqts
4.3.6.0979
qnapqts
4.3.6.0993
qnapqts
4.3.6.1013
qnapqts
4.3.6.1033
qnapqts
4.3.6.1070
qnapqts
4.3.6.1154
qnapqts
4.3.6.1218
qnapqts
4.3.6.1263
qnapqts
4.3.6.1286
qnapqts
4.3.6.1333
qnapqts
4.3.6.1411
qnapqts
4.3.6.1446
qnapqts
4.5.1
qnapqts
4.5.1.1456
qnapqts
4.5.1.1461
qnapqts
4.5.1.1465
qnapqts
4.5.1.1480
qnapqts
4.5.2
𝑥
= Vulnerable software versions