PT-2020-8654 · Qnap · Qnap Qts

Published

2020-12-31

·

Updated

2021-01-06

·

CVE-2018-19945

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: QNAP QTS versions 4.3.4 through 4.3.6
Description: A vulnerability has been reported that affects QNAP devices, caused by improper limitations of a pathname to a restricted directory. This issue allows for renaming arbitrary files on the target system if exploited.
Recommendations: For QTS versions 4.3.4 through 4.3.6, update to QTS 4.3.6.0895 build 20190328 (or later) or QTS 4.3.4.0899 build 20190322 (or later) to resolve the issue.

Fix

Improper Access Control

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19945

Affected Products

Qnap Qts