ZeroHour

CVE-2018-19943

KEV ransomwaremass

Cross-Site Scripting in QNAP File Station on QTS NAS

CISA: QNAP NAS File Station Cross-Site Scripting Vulnerability

CVSS 3.1
5.4 medium
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2018-19943 is a cross-site scripting flaw in the File Station web application of QNAP NAS devices running the QTS operating system, allowing a remote attacker with low privileges to inject malicious code that executes in a user's browser (the CVSS vector requires user interaction and grants limited confidentiality/integrity impact). An attacker who tricks a logged-in File Station user into triggering the injected script could run actions in that user's session on the NAS. Any QNAP NAS running affected QTS 4.2.x through 4.4.x branches before the fixed builds is affected, with exposure highest for devices whose File Station web interface is reachable from the internet. The vulnerability is confirmed exploited in the wild: CISA added it to the KEV catalog on 2022-05-24 and notes known ransomware use, and the EPSS score of 17.7% (97th percentile) indicates an elevated near-term exploitation likelihood. No public proof-of-concept is known, but the KEV listing and ransomware involvement indicate real-world exploitation.

What to do: Upgrade affected NAS devices to one of the fixed QTS builds: 4.4.2.1270 (20200410), 4.4.1.1261 (20200330), 4.3.6.1263 (20200330), 4.3.4.1282 (20200408), 4.3.3.1252 (20200409), or 4.2.6 build 20200421, or later. Because the flaw is on the CISA KEV list with known ransomware use, prioritize internet-facing devices: disable or firewall File Station (and other QTS web services) from direct internet access, restrict access via VPN or allowlists, and review NAS logs for signs of compromise.

Affected
QNAP QTS (File Station)QTS 4.4.2 before 4.4.2.1270 build 20200410; QTS 4.4.1 before 4.4.1.1261 build 20200330; QTS 4.3.6 before 4.3.6.1263 build 20200330; QTS 4.3.4 before 4.3.4.1282
Estimated exposure
masson the order of millions of QNAP NAS units running affected QTS 4.2.x–4.4.x releases, with tens of thousands of QNAP devices visible internet-exposed in public… — QNAP is one of the largest NAS vendors with a multi-million-unit installed base, and File Station is a core QTS component, while public internet scans (e.g., Shodan/Censys) typically show tens of thousands of QTS devices directly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CISA Known Exploited Vulnerability
Affected
QNAP Network Attached Storage (NAS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
qts
Weakness
CWE-79, CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.