CVE Published: 24/12/2020 |
CVE Updated: 17/09/2024 |
CVE Year: 2020 Source: qnap |
Vendor: QNAP Systems Inc. |
Product: QES Status : PUBLISHED
CVE-2020-2504 Description
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Metrics
CVSS Version: 3.1 |
Base Score: 5.8 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N