PT-2021-11107 · Qnap · Quts Hero+1
Published
2021-01-11
·
Updated
2021-01-14
·
CVE-2020-2508
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
QTS versions prior to 4.5.1.1456 build 20201015
QuTS hero versions prior to h4.5.1.1472 build 20201031
Description:
A command injection issue has been reported, allowing attackers to execute arbitrary commands in a compromised application.
Recommendations:
For QTS versions prior to 4.5.1.1456 build 20201015, update to QTS 4.5.1.1456 build 20201015 or later.
For QuTS hero versions prior to h4.5.1.1472 build 20201031, update to QuTS hero h4.5.1.1472 build 20201031 or later.
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qts
Quts Hero