VulnerabilityAnalyzed
CVE-2019-7194
QNAP Photo Station Path Traversal Vulnerability
KEVCRITICAL 9.8EPSS 83.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.12% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
- Weakness
- CWE-22
- Affected
- qnap/photo station
- Source
- security@qnapsecurity.com.tw
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7194
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7194US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.