CVE-2020-2499 describes a hard-coded password vulnerability impacting earlier versions of QNAP QES. This flaw allows attackers to log in using a pre-set password, potentially leading to full compromise of the affected system. With a CVSS score of 7.2 (High), the vulnerability is network-exploitable with low attack complexity, requiring high privileges but resulting in high impact to confidentiality, integrity, and availability. While QNAP has released fixes in QES 2.1.1 Build 20200515 and later, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal, indicating limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.1CPE matchmatch criteria | cpe:2.3:a:qnap:qes:*:*:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:a:qnap:qes:2.1.1:-:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:a:qnap:qes:2.1.1:build_20200211:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:a:qnap:qes:2.1.1:build_20200303:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:a:qnap:qes:2.1.1:build_20200319:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.