Skip to main content

Use of Hard-coded Password

CVE-2020-2499

Severity Medium
Score 6.3/10

Summary

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

  • LOW
  • LOCAL
  • HIGH
  • CHANGED
  • REQUIRED
  • HIGH
  • LOW
  • NONE

CWE-259 - Use of Hard-coded Password

The software contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

References

Advisory Timeline

  • Published