VulnerabilityAnalyzed
CVE-2019-7193
QNAP QTS Improper Input Validation Vulnerability
KEVCRITICAL 9.8EPSS 14.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 14.37% probability · 96th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
- Weakness
- CWE-20
- Affected
- qnap/qts
- Source
- security@qnapsecurity.com.tw
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7193
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7193US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.