CVE-2018-19949

QNAP Network Attached Storage (NAS): NAS File Station Command Injection

As of , CVE-2018-19949 in QNAP Network Attached Storage (NAS) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 24 May 2022
US federal deadline
14 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.28Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 24 May 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

CISA's description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

The CVE record's description, from qnap

CVE published
28 October 2020
Assigned by
qnap
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-20
Improper Input Validation
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Network Attached Storage (NAS): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2021-28799NAS Improper AuthorizationQNAP Network Attached Storage (NAS)Patch this weekRansomware use; EPSS 0.780.78
CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29
CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21

Read further