
Cloud Vulnerability DB
A community-led vulnerabilities database
A stored cross-site scripting vulnerability (CVE-2020-2503) was discovered in QNAP NAS systems running QES operating system. The vulnerability was disclosed on December 23, 2020, affecting earlier versions of QES before version 2.1.1 Build 20201006. This security flaw specifically impacted the File Station component of the QES system (QNAP Advisory).
The vulnerability is classified as a stored cross-site scripting (XSS) issue that affects the File Station component in QNAP QES systems. When successfully exploited, it allows remote attackers to inject malicious code into the File Station application (QNAP Advisory).
If successfully exploited, this vulnerability could allow remote attackers to inject and execute malicious code within the File Station application context, potentially leading to unauthorized access to sensitive information or manipulation of the application's behavior (QNAP Advisory).
The vulnerability requires remote access to the affected QNAP NAS system running QES to be exploited. No specific details about exploitation in the wild have been publicly disclosed (QNAP Advisory).
QNAP has addressed this vulnerability in QES version 2.1.1 Build 20201006 and later releases. Users are recommended to update their QES to the latest version through the Control Panel > System > Firmware Update path or by downloading the update manually from the QNAP website's Download Center (QNAP Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."