Vulnerability Intelligence Report
improper access control vulnerability in Helpdesk
CVE-2020-2506
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
EPSS Probability:1.98%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284 Improper Access Control
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| QNAP Systems Inc. | Helpdesk | unspecified < 3.0.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | QNAP Systems, Inc. · Vendor · Taiwan |
| Reserved | 2019-12-09T00:00:00 |
| Published | 2021-02-03T15:51:38 |
| Patch Date | 2020-10-07 |
| Last Updated | 2025-10-21T23:35:29 |
Community Chatter & Buzz