← volver
CVE-2020-36198

Command Injection Vulnerability in Malware Remover

CVSS 6.7 MEDIUMEPSS 1.1%CWE-77CWE-78
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.7EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 may 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →