CVE-2018-19953

QNAP Network Attached Storage (NAS): NAS File Station Cross-Site Scripting

As of , CVE-2018-19953 in QNAP Network Attached Storage (NAS) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 24 May 2022
US federal deadline
14 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.29Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 24 May 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

CISA's description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

The CVE record's description, from qnap

CVE published
28 October 2020
Assigned by
qnap
CVSS
6.1 Medium (CVSS 3.1, from CISA-ADP)
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Network Attached Storage (NAS): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2021-28799NAS Improper AuthorizationQNAP Network Attached Storage (NAS)Patch this weekRansomware use; EPSS 0.780.78
CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21

Read further