Vulnerability Name: | CVE-2020-36198 (CCN-201843) | ||||||||||||
Assigned: | 2021-05-13 | ||||||||||||
Published: | 2021-05-13 | ||||||||||||
Updated: | 2022-04-26 | ||||||||||||
Summary: | A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x. | ||||||||||||
CVSS v3 Severity: | 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-36198 Source: MISC Type: Patch, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/162849/QNAP-MusicStation-MalwareRemover-File-Upload-Command-Injection.html Source: XF Type: UNKNOWN qnap-cve202036198-cmd-exec(201843) Source: CCN Type: Packet Storm Security [05-28-2021] QNAP MusicStation / MalwareRemover File Upload / Command Injection Source: CCN Type: QNAP QSA-21-16 Command Injection Vulnerability in Malware Remover Source: MISC Type: Vendor Advisory https://www.qnap.com/zh-tw/security-advisory/qsa-21-16 Source: CCN Type: ZDI-21-592 QNAP NAS Malware Remover Command Injection Privilege Escalation Vulnerability Source: MISC Type: Third Party Advisory, VDB Entry https://www.zerodayinitiative.com/advisories/ZDI-21-592/ | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |