9.8

CVE-2019-7192

Warnung
Exploit

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QnapPhoto Station Version < 6.0.3
   QnapQts Version4.4.1
QnapPhoto Station Version < 5.7.10
   QnapQts Version >= 4.3.4 <= 4.4.0
QnapPhoto Station Version < 5.4.9
   QnapQts Version >= 4.3.0 <= 4.3.3
QnapPhoto Station Version < 5.2.11
   QnapQts Version4.2.6

08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

QNAP Photo Station Improper Access Control Vulnerability

Schwachstelle

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.07% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.