PT-2020-8654 · Qnap · Qnap Qts
Published
2020-12-31
·
Updated
2021-01-06
·
CVE-2018-19945
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
QNAP QTS versions 4.3.4 through 4.3.6
Description:
A vulnerability has been reported that affects QNAP devices, caused by improper limitations of a pathname to a restricted directory. This issue allows for renaming arbitrary files on the target system if exploited.
Recommendations:
For QTS versions 4.3.4 through 4.3.6, update to QTS 4.3.6.0895 build 20190328 (or later) or QTS 4.3.4.0899 build 20190322 (or later) to resolve the issue.
Fix
Improper Access Control
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnap Qts