9.8

CVE-2019-7192

Warning
Exploit

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Data is provided by the National Vulnerability Database (NVD)
QnapPhoto Station Version < 6.0.3
   QnapQts Version4.4.1
QnapPhoto Station Version < 5.7.10
   QnapQts Version >= 4.3.4 <= 4.4.0
QnapPhoto Station Version < 5.4.9
   QnapQts Version >= 4.3.0 <= 4.3.3
QnapPhoto Station Version < 5.2.11
   QnapQts Version4.2.6

08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

QNAP Photo Station Improper Access Control Vulnerability

Vulnerability

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.07% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.