SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7197

A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS.

MEDIUM 4.8EPSS 1.15%

Does this matter?

Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.

Description

A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
qnap/qts
Source
security@qnapsecurity.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.