SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-7192

QNAP Photo Station Improper Access Control Vulnerability

KEVCRITICAL 9.8EPSS 88.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
88.21% probability · 100th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
Weakness
CWE-863
Affected
qnap/photo station
Source
security@qnapsecurity.com.tw

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7192

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.