A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS build 20200702 (and later)


CWE-ID CWE Name Source
CWE-311 Missing Encryption of Sensitive Data QNAP Systems, Inc.  
CWE-319 Cleartext Transmission of Sensitive Information QNAP Systems, Inc.  

QNAP Systems, Inc.