Description
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
No analysis available yet.
Remediation
Vendor Solution
QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1491 build 20201119 and later QTS 4.5.1.1495 build 20201123 and later This issue does not affect QTS 4.3.x and QTS 4.2.x.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18480 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-20-20 |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:28:10.857Z
Reserved: 2020-09-23T00:00:00.000Z
Link: CVE-2020-25847
No data.
Status : Modified
Published: 2020-12-29T07:15:13.213
Modified: 2024-11-21T05:18:53.777
Link: CVE-2020-25847
No data.
OpenCVE Enrichment
No data.
EUVD