CVE-2019-7193
QNAP QTS Improper Input Validation Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Esta vulnerabilidad de comprobación de entrada inapropiada permite a atacantes remotos inyectar código arbitrario al sistema. Para corregir la vulnerabilidad, QNAP recomienda actualizar QTS a sus últimas versiones.
QNAP QTS and Photo Station version 6.0.3 suffers from a remote command execution vulnerability.
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-29 CVE Reserved
- 2019-12-05 CVE Published
- 2022-06-08 Exploited in Wild
- 2022-06-22 KEV Due Date
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-08-21 EPSS Updated
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | 2024-06-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0895 Search vendor "Qnap" for product "Qts" and version "4.3.6.0895" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0907 Search vendor "Qnap" for product "Qts" and version "4.3.6.0907" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0923 Search vendor "Qnap" for product "Qts" and version "4.3.6.0923" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0944 Search vendor "Qnap" for product "Qts" and version "4.3.6.0944" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0959 Search vendor "Qnap" for product "Qts" and version "4.3.6.0959" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0979 Search vendor "Qnap" for product "Qts" and version "4.3.6.0979" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.0993 Search vendor "Qnap" for product "Qts" and version "4.3.6.0993" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.1013 Search vendor "Qnap" for product "Qts" and version "4.3.6.1013" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.3.6.1033 Search vendor "Qnap" for product "Qts" and version "4.3.6.1033" | - |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.0948 Search vendor "Qnap" for product "Qts" and version "4.4.1.0948" | beta |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.0949 Search vendor "Qnap" for product "Qts" and version "4.4.1.0949" | beta |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.0978 Search vendor "Qnap" for product "Qts" and version "4.4.1.0978" | beta_2 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.0998 Search vendor "Qnap" for product "Qts" and version "4.4.1.0998" | beta_3 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.0999 Search vendor "Qnap" for product "Qts" and version "4.4.1.0999" | beta_3 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.1031 Search vendor "Qnap" for product "Qts" and version "4.4.1.1031" | beta_4 |
Affected
| ||||||
Qnap Search vendor "Qnap" | Qts Search vendor "Qnap" for product "Qts" | 4.4.1.1033 Search vendor "Qnap" for product "Qts" and version "4.4.1.1033" | beta_4 |
Affected
|