Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19945

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 8.5
Products affected by CVE-2018-19945
  • Qnap » Qts » Version: 4.3.4
    cpe:2.3:o:qnap:qts:4.3.4
  • Qnap » Qts » Version: 4.3.4.0358
    cpe:2.3:o:qnap:qts:4.3.4.0358
  • Qnap » Qts » Version: 4.3.4.0370
    cpe:2.3:o:qnap:qts:4.3.4.0370
  • Qnap » Qts » Version: 4.3.4.0372
    cpe:2.3:o:qnap:qts:4.3.4.0372
  • Qnap » Qts » Version: 4.3.4.0374
    cpe:2.3:o:qnap:qts:4.3.4.0374
  • Qnap » Qts » Version: 4.3.4.0387
    cpe:2.3:o:qnap:qts:4.3.4.0387
  • Qnap » Qts » Version: 4.3.4.0411
    cpe:2.3:o:qnap:qts:4.3.4.0411
  • Qnap » Qts » Version: 4.3.4.0416
    cpe:2.3:o:qnap:qts:4.3.4.0416
  • Qnap » Qts » Version: 4.3.4.0427
    cpe:2.3:o:qnap:qts:4.3.4.0427
  • Qnap » Qts » Version: 4.3.4.0434
    cpe:2.3:o:qnap:qts:4.3.4.0434
  • Qnap » Qts » Version: 4.3.4.0435
    cpe:2.3:o:qnap:qts:4.3.4.0435
  • Qnap » Qts » Version: 4.3.4.0451
    cpe:2.3:o:qnap:qts:4.3.4.0451
  • Qnap » Qts » Version: 4.3.4.0483
    cpe:2.3:o:qnap:qts:4.3.4.0483
  • Qnap » Qts » Version: 4.3.4.0486
    cpe:2.3:o:qnap:qts:4.3.4.0486
  • Qnap » Qts » Version: 4.3.4.0506
    cpe:2.3:o:qnap:qts:4.3.4.0506
  • Qnap » Qts » Version: 4.3.4.0516
    cpe:2.3:o:qnap:qts:4.3.4.0516
  • Qnap » Qts » Version: 4.3.4.0526
    cpe:2.3:o:qnap:qts:4.3.4.0526
  • Qnap » Qts » Version: 4.3.4.0551
    cpe:2.3:o:qnap:qts:4.3.4.0551
  • Qnap » Qts » Version: 4.3.4.0557
    cpe:2.3:o:qnap:qts:4.3.4.0557
  • Qnap » Qts » Version: 4.3.4.0561
    cpe:2.3:o:qnap:qts:4.3.4.0561
  • Qnap » Qts » Version: 4.3.4.0569
    cpe:2.3:o:qnap:qts:4.3.4.0569
  • Qnap » Qts » Version: 4.3.4.0593
    cpe:2.3:o:qnap:qts:4.3.4.0593
  • Qnap » Qts » Version: 4.3.4.0597
    cpe:2.3:o:qnap:qts:4.3.4.0597
  • Qnap » Qts » Version: 4.3.4.0604
    cpe:2.3:o:qnap:qts:4.3.4.0604
  • Qnap » Qts » Version: 4.3.5
    cpe:2.3:o:qnap:qts:4.3.5
  • Qnap » Qts » Version: 4.3.6
    cpe:2.3:o:qnap:qts:4.3.6


Contact Us

Shodan ® - All rights reserved