CISA Known Exploited Vulnerability

CVE-2020-2506

QNAP Systems · Helpdesk

QNAP Helpdesk Improper Access Control Vulnerability

Date added
BOD 22-01 due date
CWE CWE-284
Ransomware Unknown

CISA description

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

Required action

Apply updates per vendor instructions.