Back

CRITICAL KEV Used in ransomware campaigns

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

Published Oct 28, 2020 ·Due Jun 14, 2022

Description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (3)
  1. CISA ADP
    • SSVC automatable changed from no to yes
  2. CISA ADP
    • SSVC automatable changed from yes to no
  3. CISA ADP
    • SSVC automatable changed from no to yes
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner qnap
Published Oct 28, 2020
Updated Oct 2, 2026
Reserved Dec 7, 2018
CISA Vulnrichment
Updated Jun 1, 2022
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a