TROYANOSYVIRUS
Retour aux CVEs

CVE-2018-19949

CRITICALCISA KEV
9.8

Description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/28/2020
Derniere modification11/3/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurQNAP
ProduitNetwork Attached Storage (NAS)
Nom vulnerabiliteQNAP NAS File Station Command Injection Vulnerability
Date ajout KEV2022-05-24
Date limite remediation2022-06-14
Utilise dans ransomwareKnown

Produits affectes

qnap:qts

Faiblesses (CWE)

CWE-20CWE-77CWE-78CWE-77

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.