{"cve":{"cve_id":"CVE-2020-2506","is_kev":true,"kev_date_added":"2022-03-25","kev_vendor_project":"QNAP Systems","kev_product":"Helpdesk","kev_vulnerability_name":"QNAP Helpdesk Improper Access Control Vulnerability","kev_short_description":"QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.","kev_required_action":"Apply updates per vendor instructions.","kev_due_date":"2022-04-15","kev_known_ransomware":false,"kev_notes":"https://nvd.nist.gov/vuln/detail/CVE-2020-2506","kev_cwes":["CWE-284"],"epss_score":0.01982,"epss_percentile":0.77977,"epss_as_of":"2026-06-23","description":"The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.","published_at":"2021-02-03T15:51:38.031000Z","last_modified_at":null,"cvss_v3_score":7.3,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":true,"ssvc_technical_impact":"partial","cwes":["CWE-284"],"nvd_references":["https://www.qnap.com/zh-tw/security-advisory/qsa-20-08"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-06-28T23:13:53.256646Z"},"effective_severity":"HIGH","badges":["kev"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"L","value_label":"Low"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"L","value_label":"Low"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"qnap-systems-inc.","vendor_name":"QNAP Systems Inc.","product_slug":"helpdesk","product_name":"Helpdesk","version_start":"unspecified","version_start_inclusive":true,"version_end":"3.0.3","version_end_inclusive":false,"cpe23_uri":"cve5:qnap-systems-inc.:helpdesk:unspecified:3.0.3"}],"exploit_refs":[],"news":[],"references":[{"url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-08","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2021-02-03T15:51:38.031000Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2022-03-25T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-06-24T00:31:29.914509Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:29.914509Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:29.914509Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:29.914509Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:29.914509Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:29.914509Z","label":"CVSS score revised","source":"vulnrichment"}]}