Home
MEDIUM: 4.4 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:UDefault status
unaffected
7.13.x (custom) before 7.13.0
affected
Default status
unaffected
5.1.x (custom) before 5.1.5
affected
Default status
unaffected
2.2.x (custom) before 2.2.8
affected
Description
A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later
Problem types
Product status
7.13.x (custom) before 7.13.0
5.1.x (custom) before 5.1.5
2.2.x (custom) before 2.2.8
Credits
Michael Cowell
References
www.qnap.com/en/security-advisory/qsa-25-55
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.