SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-7193

QNAP QTS Improper Input Validation Vulnerability

KEVCRITICAL 9.8EPSS 14.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
14.37% probability · 96th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
Weakness
CWE-20
Affected
qnap/qts
Source
security@qnapsecurity.com.tw

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7193

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.