← Back

CVE-2018-19949

nvd nist
Published: Oct 28, 2020Modified: Nov 3, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

Affected (12)

Products: Qnap: Qts
1 product
Qts
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Before 4.2.6
From 4.3.1.0013 to 4.3.3.1161
From 4.3.4 to 4.3.4.1190
From 4.3.6 to 4.3.6.1218
From 4.4.0 to 4.4.1.1201
From 4.4.2 to 4.4.2.1231
Version 4.2.6
Version 4.2.6 build_20170517
Version 4.2.6 build_20190322
Version 4.2.6 build_20190730
Version 4.2.6 build_20190921
Version 4.2.6 build_20191107

References (3)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.