Vulnerability Description
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Photo Station | < 6.0.3 |
| Qnap | Qts | 4.4.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-RemExploitThird Party AdvisoryVDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-RemExploitThird Party AdvisoryVDB Entry
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-US Government Resource
FAQ
What is CVE-2019-7194?
CVE-2019-7194 is a vulnerability with a CVSS score of 9.8 (CRITICAL). This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versi...
How severe is CVE-2019-7194?
CVE-2019-7194 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-7194?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Photo Station, Qnap Qts.