CVE-2018-19941
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)
Scoring
- CVSS base score
- 0.01
- EPSS probability
- 0.15%
- CWE
- CWE-315
- Published
- 2020-12-31
- Last modified
- 2026-03-14
Affected products
- QNAP Systems Inc. QTS
- QNAP Systems Inc. QuTS hero
- QNAP Systems Inc. QuTScloud
Weakness type
Related vulnerabilities
- CVE-2025-8528 — Exrick xboot getMenuList sensitive information in a cookie
- CVE-2025-4537 — yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
- CVE-2024-8644 — Cleartext Storage of Sensitive Information in Oceanic Software's ValeApp
- CVE-2024-24768 — 1Panel set-cookie is missing the Secure keyword
- CVE-2021-34564 — In WirelessHART-Gateway versions 3.0.9 a vulnerability allows to read and write sensitive data in a cookie