VYPR
High severity7.5NVD Advisory· Published Oct 28, 2020· Updated Jun 17, 2026

CVE-2020-24990

CVE-2020-24990

Description

An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • QSC/Q Sys Core Managerllm-fuzzy3 versions
    =8.2.1+ 2 more
    • (no CPE)range: =8.2.1
    • cpe:2.3:a:qsc:q-sys_core_manager:8.2.1:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.