CVE-2020-36198
Command Injection Vulnerability in Malware Remover
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.
Se ha reportado una vulnerabilidad de inyección de comandos que afecta a determinadas versiones de Malware Remover. Si es explotada, esta vulnerabilidad permite a atacantes remotos ejecutar comandos arbitrarios. Este problema afecta a: QNAP Systems Inc. Malware Remover versiones anteriores a 4.6.1.0. Este problema no afecta a: QNAP Systems Inc. Malware Remover versión 3.x
This vulnerability allows local attackers to escalate privileges on affected installations of QNAP NAS. Authentication is required to exploit this vulnerability.
The specific flaw exists within the Malware Remover application. A crafted TAR file in the file system can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the admin user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-19 CVE Reserved
- 2021-05-13 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-592 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/162849/QNAP-MusicStation-MalwareRemover-File-Upload-Command-Injection.html | 2022-04-26 |
URL | Date | SRC |
---|---|---|
https://www.qnap.com/zh-tw/security-advisory/qsa-21-16 | 2022-04-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Malware Remover Search vendor "Qnap" for product "Malware Remover" | >= 4.5.4.0 < 4.6.1.0 Search vendor "Qnap" for product "Malware Remover" and version " >= 4.5.4.0 < 4.6.1.0" | - |
Affected
|