SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-7194

QNAP Photo Station Path Traversal Vulnerability

KEVCRITICAL 9.8EPSS 83.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
83.12% probability · 100th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
Weakness
CWE-22
Affected
qnap/photo station
Source
security@qnapsecurity.com.tw

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7194

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.