VulnerabilityAnalyzed
CVE-2019-7192
QNAP Photo Station Improper Access Control Vulnerability
KEVCRITICAL 9.8EPSS 88.2%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 88.21% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
- Weakness
- CWE-863
- Affected
- qnap/photo station
- Source
- security@qnapsecurity.com.tw
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7192
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7192US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.