CVE-2019-9945

UnknownEPSS 5.85%

Last modified

CVE-2019-9945 is a vulnerability of currently unknown severity. SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. EPSS estimates a 5.85% chance of exploitation in the next 30 days.

Description

SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirected to the login page. An arbitrary value can be provided for this cookie to access the web interface without valid user credentials. If customers have not followed SoftNAS deployment best practices and expose SoftNAS StorageCenter ports directly to the internet, this vulnerability allows an attacker to gain access to the Webadmin interface to create new users or execute arbitrary commands with administrative privileges, compromising both the platform and the data.

Metrics

EPSS Probability
5.85%

92.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SoftnasCloud4.2.0
SoftnasCloud4.2.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-9945?
SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirected to the login page. An arbitrary value can be provided for this cookie to access the web interface without valid user credentials. If customers have not followed SoftNAS deployment best practices and expose SoftNAS StorageCenter ports directly to the internet, this vulnerability allows an attacker to gain access to the Webadmin interface to create new users or execute arbitrary commands with administrative privileges, compromising both the platform and the data.
How severe is CVE-2019-9945?
Severity scoring for CVE-2019-9945 is pending analysis. The EPSS model estimates a 5.85% probability of exploitation in the next 30 days.
How do I fix CVE-2019-9945?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-9945?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST