CVE-2018-19943

QNAP Network Attached Storage (NAS): NAS File Station Cross-Site Scripting

As of , CVE-2018-19943 in QNAP Network Attached Storage (NAS) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 24 May 2022
US federal deadline
14 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.21Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 24 May 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

CISA's description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

The CVE record's description, from qnap

CVE published
28 October 2020
Assigned by
qnap
CVSS
8.0 High (CVSS 3.1, from the CNA)
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Network Attached Storage (NAS): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2021-28799NAS Improper AuthorizationQNAP Network Attached Storage (NAS)Patch this weekRansomware use; EPSS 0.780.78
CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29

Read further