CVE-2020-2504

MEDIUM

QNAP QES < 2.1.1 - Path Traversal in File Station

Title source: llm
STIX 2.1

Description

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

References (1)

Core 1
Core References

Scores

CVSS v3 5.8
EPSS 0.0035
EPSS Percentile 57.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-22 CWE-284 CWE-20 CWE-73
Status published
Products (2)
qnap/qes 2.1.1 (7 CPE variants)
qnap/qes < 2.1.1
Published Dec 24, 2020
Tracked Since Feb 18, 2026