Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-19957


A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later


Published

2021-09-10T04:15:08.857

Last Modified

2024-11-21T03:58:53.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-1021
  • Type: Primary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qnap qts < 4.5.4.1715 Yes
Operating System qnap quts_hero < h4.5.4.1771 Yes
Operating System qnap qutscloud < c4.5.6.1755 Yes

References