CVE-2018-19943
Summary
| CVE | CVE-2018-19943 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-28 18:15:00 UTC |
| Updated | 2020-11-13 16:29:00 UTC |
| Description | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later |
Risk And Classification
EPSS: 0.177050000 probability, percentile 0.968390000 (date 2026-07-22)
CISA KEV: Listed on 2022-05-24; due 2022-06-14; ransomware use Known
Problem Types: CWE-79
CISA Known Exploited Vulnerability
| Vendor | QNAP |
|---|---|
| Product | Network Attached Storage (NAS) |
| Name | QNAP NAS File Station Cross-Site Scripting Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-19943 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Qnap | Qts | All | All | All | All |
| Operating System | Qnap | Qts | 4.2.6 | - | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20170517 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190322 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190730 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190921 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20191107 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200109 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200421 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200611 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200821 | All | All |
| Operating System | Qnap | Qts | All | All | All | All |
| Operating System | Qnap | Qts | 4.2.6 | - | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20170517 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190322 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190730 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20190921 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20191107 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200109 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200421 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200611 | All | All |
| Operating System | Qnap | Qts | 4.2.6 | build_20200821 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities in File Station - Security Advisory | QNAP | CONFIRM | www.qnap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: Independent Security Evaluators
Legacy QID Mappings
- 731240 QNAP QTS Multiple Security Vulnerabilities (QSA-20-01)