CVE-2018-19943
KEV ransomwaremassCross-Site Scripting in QNAP File Station on QTS NAS
CISA: QNAP NAS File Station Cross-Site Scripting Vulnerability
CVE-2018-19943 is a cross-site scripting flaw in the File Station web application of QNAP NAS devices running the QTS operating system, allowing a remote attacker with low privileges to inject malicious code that executes in a user's browser (the CVSS vector requires user interaction and grants limited confidentiality/integrity impact). An attacker who tricks a logged-in File Station user into triggering the injected script could run actions in that user's session on the NAS. Any QNAP NAS running affected QTS 4.2.x through 4.4.x branches before the fixed builds is affected, with exposure highest for devices whose File Station web interface is reachable from the internet. The vulnerability is confirmed exploited in the wild: CISA added it to the KEV catalog on 2022-05-24 and notes known ransomware use, and the EPSS score of 17.7% (97th percentile) indicates an elevated near-term exploitation likelihood. No public proof-of-concept is known, but the KEV listing and ransomware involvement indicate real-world exploitation.
What to do: Upgrade affected NAS devices to one of the fixed QTS builds: 4.4.2.1270 (20200410), 4.4.1.1261 (20200330), 4.3.6.1263 (20200330), 4.3.4.1282 (20200408), 4.3.3.1252 (20200409), or 4.2.6 build 20200421, or later. Because the flaw is on the CISA KEV list with known ransomware use, prioritize internet-facing devices: disable or firewall File Station (and other QTS web services) from direct internet access, restrict access via VPN or allowlists, and review NAS logs for signs of compromise.
| QNAP QTS (File Station) | QTS 4.4.2 before 4.4.2.1270 build 20200410; QTS 4.4.1 before 4.4.1.1261 build 20200330; QTS 4.3.6 before 4.3.6.1263 build 20200330; QTS 4.3.4 before 4.3.4.1282 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
- Affected
- QNAP Network Attached Storage (NAS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- qts
- Weakness
- CWE-79, CWE-80
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.