Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-2501

Опубликовано: 17 фев. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM CPU NAS (64bit OS) and x86 CPU NAS (64bit OS) Surveillance Station 5.1.5.3.3 (and later) for ARM CPU NAS (32bit OS) and x86 CPU NAS (32bit OS)

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*
Версия до 5.1.5.3.3 (исключая)
cpe:2.3:a:qnap:surveillance_station:*:*:*:*:*:*:*:*
Версия от 5.1.5.4.0 (включая) до 5.1.5.4.3 (исключая)
cpe:2.3:h:qnap:nas:-:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03755
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-787

Связанные уязвимости

github
больше 3 лет назад

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM CPU NAS (64bit OS) and x86 CPU NAS (64bit OS) Surveillance Station 5.1.5.3.3 (and later) for ARM CPU NAS (32bit OS) and x86 CPU NAS (32bit OS)

EPSS

Процентиль: 88%
0.03755
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-121
CWE-787