First published: Thu Dec 31 2020(Updated: )
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <4.4.3.1354 |
QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19944 is a vulnerability that allows a remote attacker to gain access to sensitive information in certain QTS devices.
CVE-2018-19944 has a severity rating of 7.5, which is considered high.
QTS versions up to and excluding 4.4.3.1354 are affected by CVE-2018-19944.
Yes, QNAP has fixed CVE-2018-19944 in QTS version 4.4.3.1354 build and later.
You can find more information about CVE-2018-19944 on the QNAP security advisory page: https://www.qnap.com/zh-tw/security-advisory/qsa-20-22