10

CVE-2019-7193

Warnung
Exploit
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version 4.3.6.0895 Update -
Qnap ≫ Qts Version 4.3.6.0907 Update -
Qnap ≫ Qts Version 4.3.6.0923 Update -
Qnap ≫ Qts Version 4.3.6.0944 Update -
Qnap ≫ Qts Version 4.3.6.0959 Update -
Qnap ≫ Qts Version 4.3.6.0979 Update -
Qnap ≫ Qts Version 4.3.6.0993 Update -
Qnap ≫ Qts Version 4.3.6.1013 Update -
Qnap ≫ Qts Version 4.3.6.1033 Update -
Qnap ≫ Qts Version 4.4.1.0948 Update beta
Qnap ≫ Qts Version 4.4.1.0949 Update beta
Qnap ≫ Qts Version 4.4.1.0978 Update beta_2
Qnap ≫ Qts Version 4.4.1.0998 Update beta_3
Qnap ≫ Qts Version 4.4.1.0999 Update beta_3
Qnap ≫ Qts Version 4.4.1.1031 Update beta_4
Qnap ≫ Qts Version 4.4.1.1033 Update beta_4

08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

QNAP QTS Improper Input Validation Vulnerability

Schwachstelle

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.37% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://www.qnap.com/zh-tw/security-advisory/nas-201911-25
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7193
US Government Resource