CVE-2018-19943
Summary
| CVE | CVE-2018-19943 |
|---|---|
| State | PUBLISHED |
| Assigner | qnap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-28 18:15:12 UTC |
| Updated | 2026-08-13 05:17:17 UTC |
| Description | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.177050000 probability, percentile 0.969200000 (date 2026-08-22)
CISA KEV: Listed on 2022-05-24; due 2022-06-14; ransomware use Known
Problem Types: CWE-79 | CWE-80 | CWE-79 CWE-79 Cross-site Scripting (XSS) | CWE-80 CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | [email protected] | Secondary | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
CISA Known Exploited Vulnerability
| Vendor | QNAP |
|---|---|
| Product | Network Attached Storage (NAS) |
| Name | QNAP NAS File Station Cross-Site Scripting Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-19943 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.4.2.1270 custom | build 20200410 |
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.4.1.1261 custom | build 20200330 |
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.3.6.1263 custom | build 20200330 |
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.3.4.1282 custom | build 20200408 |
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.3.3.1252 custom | build 20200409 |
| CNA | QNAP Systems Inc. | QTS | affected unspecified 4.2.6 custom | build 20200421 |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities in File Station - Security Advisory | QNAP | af854a3a-2127-422b-91ae-364da2661108 | www.qnap.com | Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
CNA: Independent Security Evaluators (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-05-24T00:00:00.000Z | CVE-2018-19943 added to CISA KEV |
Legacy QID Mappings
- 731240 QNAP QTS Multiple Security Vulnerabilities (QSA-20-01)