← All CVEs

CVE-2019-7193

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-06-08Remediation due 2022-06-22

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

9.8
CVSS
14.4%
EPSS (exploit prob.)
96th
EPSS percentile
2019-12-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
qnapqts4.3.6.0895
qnapqts4.3.6.0907
qnapqts4.3.6.0923
qnapqts4.3.6.0944
qnapqts4.3.6.0959
qnapqts4.3.6.0979
qnapqts4.3.6.0993
qnapqts4.3.6.1013
qnapqts4.3.6.1033
qnapqts4.4.1.0948
qnapqts4.4.1.0949
qnapqts4.4.1.0978
qnapqts4.4.1.0998
qnapqts4.4.1.0999
qnapqts4.4.1.1031
qnapqts4.4.1.1033

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-7193