A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.
2020-12-24T02:15:12.423
2024-11-21T05:25:21.283
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qnap | qes | < 2.1.1 | Yes |
Application | qnap | qes | 2.1.1 | Yes |
Application | qnap | qes | 2.1.1 | Yes |
Application | qnap | qes | 2.1.1 | Yes |
Application | qnap | qes | 2.1.1 | Yes |
Application | qnap | qes | 2.1.1 | Yes |