SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-7195

QNAP Photo Station Path Traversal Vulnerability

KEVCRITICAL 9.8EPSS 89.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
89.68% probability · 100th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022 · used in ransomware campaigns
Weakness
CWE-22
Affected
qnap/photo station
Source
security@qnapsecurity.com.tw

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7195

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.