890
VMScore

CVE-2019-7193

Published: 05/12/2019 Updated: 28/05/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

This improper input validation vulnerability allows remote malicious users to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qnap qts 4.3.6.0895

qnap qts 4.3.6.0907

qnap qts 4.3.6.0923

qnap qts 4.3.6.0944

qnap qts 4.3.6.0959

qnap qts 4.3.6.0979

qnap qts 4.3.6.0993

qnap qts 4.3.6.1013

qnap qts 4.3.6.1033

qnap qts 4.4.1.0948

qnap qts 4.4.1.0949

qnap qts 4.4.1.0978

qnap qts 4.4.1.0998

qnap qts 4.4.1.0999

qnap qts 4.4.1.1031

qnap qts 4.4.1.1033

Exploits

QNAP QTS and Photo Station version 603 suffers from a remote command execution vulnerability ...

Github Repositories

Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)

QNAP Pre-Auth Root RCE (CVE-2019-7192 ~ CVE-2019-7195) Checker Usage: pip install requests /Checker_for_QNAP_RCE_cve20197192_95py /path/to/ip-porttxt Example file input: 1234 8080 2345 443 This tool takes a list of QNAP NASes' IPs and ports, and it tells if each device is vulnerable to