2.3

CVE-2020-2505

Sensitive information via generation of error messages vulnerability in QES

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qes Version < 2.1.1
Qnap ≫ Qes Version 2.1.1 Update -
Qnap ≫ Qes Version 2.1.1 Update build_20200211
Qnap ≫ Qes Version 2.1.1 Update build_20200303
Qnap ≫ Qes Version 2.1.1 Update build_20200319
Qnap ≫ Qes Version 2.1.1 Update build_20200424
Qnap ≫ Qes Version 2.1.1 Update build_20200515
Qnap ≫ Qes Version 2.1.1 Update build_20200811
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.208
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
security@qnapsecurity.com.tw 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-209 Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

https://www.qnap.com/zh-tw/security-advisory/qsa-20-17
Vendor Advisory