CVE-2020-2499
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
24/12/2020
Last modified:
28/12/2020
Description
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:qnap:qes:*:*:*:*:*:*:*:* | 2.1.1 (excluding) | |
cpe:2.3:a:qnap:qes:2.1.1:-:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:qes:2.1.1:build_20200211:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:qes:2.1.1:build_20200303:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:qes:2.1.1:build_20200319:*:*:*:*:*:* | ||
cpe:2.3:a:qnap:qes:2.1.1:build_20200424:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page