CVE-2020-2505

LOW

Qnap Qes < 2.1.1 - Error Information Exposure

Title source: rule

Description

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Scores

CVSS v3 2.3
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-755 CWE-209
Status published

Affected Products (8)

qnap/qes < 2.1.1
qnap/qes
qnap/qes
qnap/qes
qnap/qes
qnap/qes
qnap/qes
qnap/qes

Timeline

Published Dec 24, 2020
Tracked Since Feb 18, 2026