← All CVEs

CVE-2020-2509

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-11Remediation due 2022-05-02

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

9.8
CVSS
33.4%
EPSS (exploit prob.)
98th
EPSS percentile
2021-04-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77CWE-78

Affected products

VendorProductAffected versions
qnapqts< 4.2.6
qnapqts>= 4.3.5, < 4.3.6
qnapqts>= 4.4.0, < 4.5.1
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.2.6
qnapqts4.3.3.0174
qnapqts4.3.3.0868
qnapqts4.3.3.0998
qnapqts4.3.3.1051
qnapqts4.3.3.1098
qnapqts4.3.3.1161
qnapqts4.3.3.1252
qnapqts4.3.3.1315
qnapqts4.3.3.1386
qnapqts4.3.3.1432
qnapqts4.3.4.0358
qnapqts4.3.4.0358
qnapqts4.3.4.0370
qnapqts4.3.4.0370
qnapqts4.3.4.0372
qnapqts4.3.4.0372
qnapqts4.3.4.0374
qnapqts4.3.4.0374
qnapqts4.3.4.0387
qnapqts4.3.4.0387
qnapqts4.3.4.0411
qnapqts4.3.4.0416
qnapqts4.3.4.0427
qnapqts4.3.4.0434
qnapqts4.3.4.0435
qnapqts4.3.4.0451
qnapqts4.3.4.0483

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-2509