Qnap QTS Cross-site Scripting (CVE-2018-19943)

medium Tenable OT Security Plugin ID 502504

Synopsis

The remote OT asset is affected by a vulnerability.

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://www.qnap.com/zh-tw/security-advisory/qsa-20-01

Plugin Details

Severity: Medium

ID: 502504

Version: 1.3

Type: remote

Family: Tenable.ot

Published: 10/16/2024

Updated: 10/17/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.6

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.9

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2018-19943

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:qnap:qts:4.4.1, cpe:/o:qnap:qts:4.3.3, cpe:/o:qnap:qts:4.3.4, cpe:/o:qnap:qts:4.3.6, cpe:/o:qnap:qts:4.2.6, cpe:/o:qnap:qts:4.4.2

Required KB Items: Tenable.ot/Qnap

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/28/2020

Vulnerability Publication Date: 10/28/2020

CISA Known Exploited Vulnerability Due Dates: 6/14/2022

Reference Information

CVE: CVE-2018-19943

CWE: 79, 80