CVE-2018-19957
Estado: ModificadaMedia (6.1)—
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.71%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-1021
- CWE-1021
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-19957",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "QTS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.5.4.1715 build 20210630",
"versionType": "custom"
}
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuTS hero",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "h4.5.4.1771 build 20210825",
"versionType": "custom"
}
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "QuTScloud",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "c4.5.6.1755 build 20210809",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-09-10T04:15:08.857",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-03",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-03",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-1021"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1021"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later"
},
{
"lang": "es",
"value": "Se ha reportado de una vulnerabilidad que implica encabezados de seguridad HTTP insuficientes y que afecta a los NAS de QNAP que ejecutan QTS, QuTS hero y QuTScloud. Esta vulnerabilidad permite a atacantes remotos iniciar ataques de privacidad y seguridad. Ya hemos corregido esta vulnerabilidad en las siguientes versiones: QTS 4.5.4.1715 build 20210630 y posteriores QuTS hero h4.5.4.1771 build 20210825 y posteriores QuTScloud c4.5.6.1755 build 20210809 y posteriores"
}
],
"lastModified": "2026-06-17T01:50:11.337",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "560D361F-6679-43FA-9164-64FCAA0563B1",
"versionEndExcluding": "4.5.4.1715"
},
{
"criteria": "cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B57DE98-C9C6-4C4D-B790-293D6D0CE646",
"versionEndExcluding": "h4.5.4.1771"
},
{
"criteria": "cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65E1E2FD-8AB8-4C29-AC6F-619CB0888620",
"versionEndExcluding": "c4.5.6.1755"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}