CVE-2019-7193
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- QNAP QTS Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 14% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-20
מוצרים מושפעים
qnap: qts
קישורים
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 Vendor Advisory
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-R… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-R… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource