CVE-2020-36195

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
qnapCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
qnapqts
𝑥
< 4.3.3
qnapqts
4.3.4 ≤
𝑥
< 4.3.6
qnapqts
4.3.3
qnapqts
4.3.3.0095
qnapqts
4.3.3.0096
qnapqts
4.3.3.0136
qnapqts
4.3.3.0154
qnapqts
4.3.3.0174
qnapqts
4.3.3.0188
qnapqts
4.3.3.0210
qnapqts
4.3.3.0229
qnapqts
4.3.3.0238
qnapqts
4.3.3.0262
qnapqts
4.3.3.0299
qnapqts
4.3.3.0351
qnapqts
4.3.3.0353
qnapqts
4.3.3.0361
qnapqts
4.3.3.0369
qnapqts
4.3.3.0378
qnapqts
4.3.3.0396
qnapqts
4.3.3.0404
qnapqts
4.3.3.0416
qnapqts
4.3.3.0418
qnapqts
4.3.3.0448
qnapqts
4.3.3.0514
qnapqts
4.3.3.0546
qnapqts
4.3.3.0570
qnapqts
4.3.3.0868
qnapqts
4.3.3.0998
qnapqts
4.3.3.1051
qnapqts
4.3.3.1098
qnapqts
4.3.3.1161
qnapqts
4.3.3.1252
qnapqts
4.3.3.1315
qnapqts
4.3.3.1386
qnapqts
4.3.3.1432
qnapqts
4.3.6
qnapqts
4.3.6.0895
qnapqts
4.3.6.0907
qnapqts
4.3.6.0923
qnapqts
4.3.6.0944
qnapqts
4.3.6.0959
qnapqts
4.3.6.0979
qnapqts
4.3.6.0993
qnapqts
4.3.6.1013
qnapqts
4.3.6.1033
qnapqts
4.3.6.1070
qnapqts
4.3.6.1154
qnapqts
4.3.6.1218
qnapqts
4.3.6.1263
qnapqts
4.3.6.1286
qnapqts
4.3.6.1333
qnapqts
4.3.6.1411
qnapqts
4.3.6.1446
qnapmedia_streaming_add-on
𝑥
< 430.1.8.10
qnapmedia_streaming_add-on
𝑥
< 430.1.8.8
qnapmultimedia_console
𝑥
< 1.3.4
𝑥
= Vulnerable software versions