CVE-2018-19957UI Misrepresentation / Clickjacking in Systems INC QTS

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 45.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateMay 24

Description

A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

NVDqnap/quts_hero< h4.5.4.1771
NVDqnap/qutscloud< c4.5.6.1755
CVEListV5qnap_systems_inc/quts_herounspecifiedh4.5.4.1771 build 20210825
CVEListV5qnap_systems_inc/qutscloudunspecifiedc4.5.6.1755 build 20210809
NVDqnap/qts< 4.5.4.1715

🔴Vulnerability Details

2
GHSA
GHSA-fcwx-wvr2-2xm2: A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud2022-05-24
CVEList
Insufficient HTTP Security Headers in QTS, QuTS hero, and QuTScloud2021-09-10
CVE-2018-19957 — UI Misrepresentation / Clickjacking | cvebase