CVE-2020-24990: Qsc Q-Sys Core Manager

High severity, CVSS 7.5. EPSS: 3.7% chance of exploitation in the next 30 days.

An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

Affected products

  • Qsc Q-Sys Core Manager: version 8.2.1 only

Published 2020-10-28. Last modified 2026-06-17.