CVE-2018-19945
Improper Limitation of a Pathname to a Restricted Directory in QTS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.
Se ha reportado de una vulnerabilidad que afecta a los dispositivos QNAP anteriores que ejecutan QTS versión 4.3.4 a la 4.3.6. Causada por limitaciones inapropiadas de un nombre de ruta en un directorio restringido, esta vulnerabilidad permite cambiar el nombre de archivos arbitrarios en el sistema de destino, si se explota. QNAP ya ha corregido esta vulnerabilidad en las siguientes versiones: QTS versión 4.3.6.0895 build 20190328 (y posterior) QTS versión 4.3.4.0899 build 20190322 (y posterior) Este problema no afecta a QTS versión 4.4.x o QTS versión 4.5.x.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-07 CVE Reserved
- 2020-12-31 CVE Published
- 2023-09-16 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-73: External Control of File Name or Path
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/zh-tw/security-advisory/qsa-20-21 | 2021-01-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.3.4 < 4.3.4.0899 Search vendor "Qnap" for product "Qts" and version " >= 4.3.4 < 4.3.4.0899" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | >= 4.3.5 < 4.3.6.0895 Search vendor "Qnap" for product "Qts" and version " >= 4.3.5 < 4.3.6.0895" | - |
Affected
|